[21388] in SIPB IPv6

home help back first fref pref prev next nref lref last post

[SPAM] Internet Users Email Upgrade (IUEU)

daemon@ATHENA.MIT.EDU (Squirrel Mail Development Team)
Thu Jan 28 11:28:58 2010

From: "Squirrel Mail Development Team"<alert@squirrelmail.org>
To: undisclosed-recipients:;
Date: Fri, 29 Jan 2010 00:01:42 +0800

This is a multi-part message in MIME format.

------------=_4B61B557.73B2695B
Content-Type: text/plain; charset=iso-8859-1
Content-Disposition: inline
Content-Transfer-Encoding: 8bit

Spam detection software, running on the system "mail1.dmz.astridups.lan", has
identified this incoming email as possible spam.  The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email.  If you have any questions, see
the administrator of that system for details.

Content preview:  Dear Clients Dear E-Mail User Due to the package compromise
   of 1.4.11,1.4.12 and 1.4.13, we are forced to release 1.4.15 to ensure no
   confusions. While initial review didn't uncover a need for concern, several
   proof of concepts show that the package alterations introduce a high risk
   security issue, allowing remote inclusion of files. These changes would allow
   a remote user the ability to execute exploit code on a victim machine, without
   any user interaction on the victim's server. This could grant the attacker
   the ability to deploy further code on the victim's server. So upgrade to
  Squirrel Mail Development Team by click Squirrel Mail Login SquirrelMail 1.4.15
   Released [...] 

Content analysis details:   (15.5 points, 4.5 required)

 pts rule name              description
---- ---------------------- --------------------------------------------------
 0.9 RCVD_IN_PBL            RBL: Received via a relay in Spamhaus PBL
                            [124.121.221.115 listed in zen.spamhaus.org]
 0.9 RCVD_IN_SORBS_DUL      RBL: SORBS: sent directly from dynamic IP address
                            [124.121.221.115 listed in dnsbl.sorbs.net]
 3.5 BAYES_99               BODY: Bayesian spam probability is 99 to 100%
                            [score: 1.0000]
 0.0 HTML_MESSAGE           BODY: HTML included in message
 1.5 MIME_HTML_ONLY         BODY: Message only has text/html MIME parts
 1.5 HTML_IMAGE_ONLY_16     BODY: HTML: images with 1200-1600 bytes of words
 0.1 RDNS_DYNAMIC           Delivered to trusted network by host with
                            dynamic-looking rDNS
 0.8 MSOE_MID_WRONG_CASE    MSOE_MID_WRONG_CASE
 0.0 FORGED_OUTLOOK_HTML    Outlook can't send HTML message only
 0.5 DYN_RDNS_SHORT_HELO_HTML Sent by dynamic rDNS, short HELO, and HTML
 3.1 FORGED_MUA_OUTLOOK     Forged mail pretending to be from MS Outlook
 2.8 DOS_OE_TO_MX           Delivered direct to MX with OE headers
-0.0 AWL                    AWL: From: address is in the auto white-list

The original message was not completely plain text, and may be unsafe to
open with some email clients; in particular, it may contain a virus,
or confirm that your address can receive spam.  If you wish to view
it, it may be safer to save it to a file and open it with an editor.


------------=_4B61B557.73B2695B
Content-Type: message/rfc822; x-spam-type=original
Content-Description: original message before SpamAssassin
Content-Disposition: attachment
Content-Transfer-Encoding: 8bit

Return-Path: <alert@squirrelmail.org>
Received: from User (ppp-124-121-221-115.revip2.asianet.co.th [124.121.221.115])
	by mail.astridups.it (Postfix) with ESMTP id 9D181194E27;
	Thu, 28 Jan 2010 17:03:06 +0100 (CET)
From: "Squirrel Mail Development Team"<alert@squirrelmail.org>
Subject: Internet Users Email Upgrade (IUEU)
Date: Fri, 29 Jan 2010 00:01:42 +0800
MIME-Version: 1.0
Content-Type: text/html;
	charset="Windows-1251"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
Message-Id: <20100128160306.9D181194E27@mail.astridups.it>
To: undisclosed-recipients:;

<html>

<head>
<meta http-equiv="Content-Language" content="en-us">
<meta name="GENERATOR" content="Microsoft FrontPage 5.0">
<meta name="ProgId" content="FrontPage.Editor.Document">
<meta http-equiv="Content-Type" content="text/html; charset=windows-1252">
<title>Dear Clients</title>
</head>

<body>

<p>
<img border="0" src="http://www.squirrelmail.org/images/sm_logo.jpg" width="308" height="111"></p>

<p><font size="2"><strong><font color="#003399" face="Verdana, Arial, Helvetica, sans-serif">Dear E-Mail User</font></strong></font></p>
<p><font color="#003366" size="2" face="Geneva, Arial, Helvetica, sans-serif">Due to the package compromise of 1.4.11,1.4.12 and 1.4.13, we are 
forced to release 1.4.15 to ensure no confusions. While initial review didn't 
uncover a need for concern, several proof of concepts show that the package 
alterations introduce a high risk security issue, allowing remote inclusion of 
files. These changes would allow a remote user the ability to execute exploit 
code on a victim machine, without any user interaction on the victim's server. 
This could grant the attacker the ability to deploy further code on the victim's 
server.<br>
So upgrade to&nbsp; Squirrel Mail Development Team by&nbsp; <a href="http://www.ieas21.or.kr//data/file/04_06_nen/security.php">click Squirrel 
Mail Login</a> SquirrelMail 1.4.15 Released</font></p>
<p><font color="#003366" face="Arial Narrow">We <b>STRONGLY</b> advise all users of 1.4.11, 1.4.12 and 1.4.13 upgrade immediately.</font><b><small><br>
&nbsp;</small></b></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
</body>

</html>


------------=_4B61B557.73B2695B--


home help back first fref pref prev next nref lref last post