[21388] in SIPB IPv6
[SPAM] Internet Users Email Upgrade (IUEU)
daemon@ATHENA.MIT.EDU (Squirrel Mail Development Team)
Thu Jan 28 11:28:58 2010
From: "Squirrel Mail Development Team"<alert@squirrelmail.org>
To: undisclosed-recipients:;
Date: Fri, 29 Jan 2010 00:01:42 +0800
This is a multi-part message in MIME format.
------------=_4B61B557.73B2695B
Content-Type: text/plain; charset=iso-8859-1
Content-Disposition: inline
Content-Transfer-Encoding: 8bit
Spam detection software, running on the system "mail1.dmz.astridups.lan", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email. If you have any questions, see
the administrator of that system for details.
Content preview: Dear Clients Dear E-Mail User Due to the package compromise
of 1.4.11,1.4.12 and 1.4.13, we are forced to release 1.4.15 to ensure no
confusions. While initial review didn't uncover a need for concern, several
proof of concepts show that the package alterations introduce a high risk
security issue, allowing remote inclusion of files. These changes would allow
a remote user the ability to execute exploit code on a victim machine, without
any user interaction on the victim's server. This could grant the attacker
the ability to deploy further code on the victim's server. So upgrade to
Squirrel Mail Development Team by click Squirrel Mail Login SquirrelMail 1.4.15
Released [...]
Content analysis details: (15.5 points, 4.5 required)
pts rule name description
---- ---------------------- --------------------------------------------------
0.9 RCVD_IN_PBL RBL: Received via a relay in Spamhaus PBL
[124.121.221.115 listed in zen.spamhaus.org]
0.9 RCVD_IN_SORBS_DUL RBL: SORBS: sent directly from dynamic IP address
[124.121.221.115 listed in dnsbl.sorbs.net]
3.5 BAYES_99 BODY: Bayesian spam probability is 99 to 100%
[score: 1.0000]
0.0 HTML_MESSAGE BODY: HTML included in message
1.5 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
1.5 HTML_IMAGE_ONLY_16 BODY: HTML: images with 1200-1600 bytes of words
0.1 RDNS_DYNAMIC Delivered to trusted network by host with
dynamic-looking rDNS
0.8 MSOE_MID_WRONG_CASE MSOE_MID_WRONG_CASE
0.0 FORGED_OUTLOOK_HTML Outlook can't send HTML message only
0.5 DYN_RDNS_SHORT_HELO_HTML Sent by dynamic rDNS, short HELO, and HTML
3.1 FORGED_MUA_OUTLOOK Forged mail pretending to be from MS Outlook
2.8 DOS_OE_TO_MX Delivered direct to MX with OE headers
-0.0 AWL AWL: From: address is in the auto white-list
The original message was not completely plain text, and may be unsafe to
open with some email clients; in particular, it may contain a virus,
or confirm that your address can receive spam. If you wish to view
it, it may be safer to save it to a file and open it with an editor.
------------=_4B61B557.73B2695B
Content-Type: message/rfc822; x-spam-type=original
Content-Description: original message before SpamAssassin
Content-Disposition: attachment
Content-Transfer-Encoding: 8bit
Return-Path: <alert@squirrelmail.org>
Received: from User (ppp-124-121-221-115.revip2.asianet.co.th [124.121.221.115])
by mail.astridups.it (Postfix) with ESMTP id 9D181194E27;
Thu, 28 Jan 2010 17:03:06 +0100 (CET)
From: "Squirrel Mail Development Team"<alert@squirrelmail.org>
Subject: Internet Users Email Upgrade (IUEU)
Date: Fri, 29 Jan 2010 00:01:42 +0800
MIME-Version: 1.0
Content-Type: text/html;
charset="Windows-1251"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
Message-Id: <20100128160306.9D181194E27@mail.astridups.it>
To: undisclosed-recipients:;
<html>
<head>
<meta http-equiv="Content-Language" content="en-us">
<meta name="GENERATOR" content="Microsoft FrontPage 5.0">
<meta name="ProgId" content="FrontPage.Editor.Document">
<meta http-equiv="Content-Type" content="text/html; charset=windows-1252">
<title>Dear Clients</title>
</head>
<body>
<p>
<img border="0" src="http://www.squirrelmail.org/images/sm_logo.jpg" width="308" height="111"></p>
<p><font size="2"><strong><font color="#003399" face="Verdana, Arial, Helvetica, sans-serif">Dear E-Mail User</font></strong></font></p>
<p><font color="#003366" size="2" face="Geneva, Arial, Helvetica, sans-serif">Due to the package compromise of 1.4.11,1.4.12 and 1.4.13, we are
forced to release 1.4.15 to ensure no confusions. While initial review didn't
uncover a need for concern, several proof of concepts show that the package
alterations introduce a high risk security issue, allowing remote inclusion of
files. These changes would allow a remote user the ability to execute exploit
code on a victim machine, without any user interaction on the victim's server.
This could grant the attacker the ability to deploy further code on the victim's
server.<br>
So upgrade to Squirrel Mail Development Team by <a href="http://www.ieas21.or.kr//data/file/04_06_nen/security.php">click Squirrel
Mail Login</a> SquirrelMail 1.4.15 Released</font></p>
<p><font color="#003366" face="Arial Narrow">We <b>STRONGLY</b> advise all users of 1.4.11, 1.4.12 and 1.4.13 upgrade immediately.</font><b><small><br>
</small></b></p>
<p> </p>
<p> </p>
</body>
</html>
------------=_4B61B557.73B2695B--