Alan Eliasen eliasen at mindspring.com
Tue Apr 6 16:28:03 UTC 2004

Rafal Smigrodzki wrote:
> Is this viral spam?

   Looks like it.  I got one of them too, with someone else's name in the "on
behalf of" slot.  I was a bit annoyed that my e-mail address showed up in the
return address, but it wasn't from me.   That "on behalf of" is an indication
that it was sent through Microsoft Outlook, which I don't use.

   The virus takes advantage of a combination of two Microsoft bugs (which is
reason not to use Outlook nor Internet Explorer.)  The IFRAME embedding would
automatically load dangerous content without you asking, and the CID: URL is
just Microsoft insanity, designed, I think, to help virus writers.  Really,
don't use IE.

   Rafal, if you can send me the original message with *all* headers intact,
we can possibly trace the virus, maybe even finding the person that's compromised.

  Alan Eliasen                 | "You cannot reason a person out of a
  eliasen at mindspring.com       |  position he did not reason himself
  http://futureboy.homeip.net/ |  into in the first place."
                               |     --Jonathan Swift

