 pslossPremium join:2002-02-24 Alpharetta, GA | reply to kpatz
Re: Call for participation! Msgr Spam investigatio said by kpatz: I don't have the full (raw) UDP headers, but I do have the following information (as reported by ipchains): Date, Time, Protocol, Source IP, Source Port, Destination IP, Destination Port, Packet Length, TOS, IP ID (sequence), flags/fragmentation offset, TTL. I also have the text of the spam itself, but not the header information in the spam packet (I can pull this from the capture logs though, they just aren't in the Access DB).
That sounds like a pretty good subset of the IP and UDP header information...it's up to you whether you want to contact Lawrence, of course.
Philip Sloss -- Feedback? e-mail: stuff@lupwa.org |
 | Count me in! Spammers target me on udp port 1026 all day everyday! I've logged 5or 6 addresses in total. I know that they hope to get a response from win2k messenger service; I always disabled the service anyway.
I must have gone to a site or was redirected against my will and my ip logged for later spam abuse. I did a dig on the addresses and sent info to their ISP, s but have yet to get a response and the spammers still are at it. |