Vacation reply || Dear friend || Some other weird subject

Hey guys, I just received this message below from two different friends, and looking at the To: field, the message seems to have been sent to everybody; which probably means that spammers somehow obtained passwords to these users' email accounts and sent the advert to all contacts in the users' address books. This appears to be worm behaviour to me. Now the question that I wish to ask is... how on earth did these spammers get these passwords? Phishing? Anyone heard of the story behind this email? It's on several sites on the net, but all that people are saying is to change your password and use a strong password etc. but my guess is that all this is an unconfirmed solution, though I believe it could work. But the problem is not that someone can send an email from my account without my consent, but that he/she can get my password. That's what worries me. So, anybody got any ideas on how this could have happened? Thanks, Me. 2009/4/28 <dicksonmwangi356@hotmail.com>
Dear friend, I would like to introduce a really good company that mainly do the electornic products trade. Now the company is doing promotion,all of it's products are sold nearly as same as their cost. It redeners the best service to customers,it provide you original products which is good quality,and what's more,the pricewill give you a big surprise! It is realy a good opportunity for doing shopping.Just grasp the opportunity,or there will be no more than that! The web address: www.kanicn.com
_______________________________________________ Skunkworks mailing list Skunkworks@lists.my.co.ke http://lists.my.co.ke/cgi-bin/mailman/listinfo/skunkworks Other services @ http://my.co.ke Other lists ------------- Skunkworks announce: http://lists.my.co.ke/cgi-bin/mailman/listinfo/skunkworks-announce Science - http://lists.my.co.ke/cgi-bin/mailman/listinfo/science kazi - http://lists.my.co.ke/cgi-bin/mailman/admin/kazi/general
-- שִׁמְעוֹן

It happened to me! And my first instinct was to change my password. Still puzzled as to what could have caused it. On 5/17/09, Simon Mbuthia <simon.mbuthia@gmail.com> wrote:
Hey guys,
I just received this message below from two different friends, and looking at the To: field, the message seems to have been sent to everybody; which probably means that spammers somehow obtained passwords to these users' email accounts and sent the advert to all contacts in the users' address books. This appears to be worm behaviour to me. Now the question that I wish to ask is... how on earth did these spammers get these passwords? Phishing?
Anyone heard of the story behind this email? It's on several sites on the net, but all that people are saying is to change your password and use a strong password etc. but my guess is that all this is an unconfirmed solution, though I believe it could work. But the problem is not that someone can send an email from my account without my consent, but that he/she can get my password. That's what worries me.
So, anybody got any ideas on how this could have happened?
Thanks,
Me.
2009/4/28 <dicksonmwangi356@hotmail.com>
Dear friend, I would like to introduce a really good company that mainly do the electornic products trade. Now the company is doing promotion,all of it's products are sold nearly as same as their cost. It redeners the best service to customers,it provide you original products which is good quality,and what's more,the pricewill give you a big surprise! It is realy a good opportunity for doing shopping.Just grasp the opportunity,or there will be no more than that! The web address: www.kanicn.com
_______________________________________________ Skunkworks mailing list Skunkworks@lists.my.co.ke http://lists.my.co.ke/cgi-bin/mailman/listinfo/skunkworks Other services @ http://my.co.ke Other lists ------------- Skunkworks announce: http://lists.my.co.ke/cgi-bin/mailman/listinfo/skunkworks-announce Science - http://lists.my.co.ke/cgi-bin/mailman/listinfo/science kazi - http://lists.my.co.ke/cgi-bin/mailman/admin/kazi/general
-- שִׁמְעוֹן
-- Regards, Martin Kamau

Hi guys, I also got this from a friend of mine, i snooped around google and found that the account was pwned.Please notify your friends and tell them to change their passwords and also look in their sent mail. On Sun, May 17, 2009 at 11:37 PM, Martin Gachunga <gachunga@gmail.com>wrote:
It happened to me! And my first instinct was to change my password. Still puzzled as to what could have caused it.
On 5/17/09, Simon Mbuthia <simon.mbuthia@gmail.com> wrote:
Hey guys,
I just received this message below from two different friends, and looking at the To: field, the message seems to have been sent to everybody; which probably means that spammers somehow obtained passwords to these users' email accounts and sent the advert to all contacts in the users' address books. This appears to be worm behaviour to me. Now the question that I wish to ask is... how on earth did these spammers get these passwords? Phishing?
Anyone heard of the story behind this email? It's on several sites on the net, but all that people are saying is to change your password and use a strong password etc. but my guess is that all this is an unconfirmed solution, though I believe it could work. But the problem is not that someone can send an email from my account without my consent, but that he/she can get my password. That's what worries me.
So, anybody got any ideas on how this could have happened?
Thanks,
Me.
2009/4/28 <dicksonmwangi356@hotmail.com>
Dear friend, I would like to introduce a really good company that mainly do the electornic products trade. Now the company is doing promotion,all of it's products are sold nearly as same as their cost. It redeners the best service to customers,it provide you original products which is good quality,and what's more,the pricewill give you a big surprise! It is realy a good opportunity for doing shopping.Just grasp the opportunity,or there will be no more than that! The web address: www.kanicn.com
_______________________________________________ Skunkworks mailing list Skunkworks@lists.my.co.ke http://lists.my.co.ke/cgi-bin/mailman/listinfo/skunkworks Other services @ http://my.co.ke Other lists ------------- Skunkworks announce: http://lists.my.co.ke/cgi-bin/mailman/listinfo/skunkworks-announce Science - http://lists.my.co.ke/cgi-bin/mailman/listinfo/science kazi - http://lists.my.co.ke/cgi-bin/mailman/admin/kazi/general
-- שִׁמְעוֹן
-- Regards, Martin Kamau _______________________________________________ Skunkworks mailing list Skunkworks@lists.my.co.ke http://lists.my.co.ke/cgi-bin/mailman/listinfo/skunkworks Other services @ http://my.co.ke Other lists ------------- Skunkworks announce: http://lists.my.co.ke/cgi-bin/mailman/listinfo/skunkworks-announce Science - http://lists.my.co.ke/cgi-bin/mailman/listinfo/science kazi - http://lists.my.co.ke/cgi-bin/mailman/admin/kazi/general

Phishing, i think. Some guys are send links that urge them to change their password or log on. The links lead to sites that look like your webmail log in page. Alternatively, they have also discovered that people use the same passwords online, so they just get you to register to use another site (offering free downloads etc) and then use your password to get your mail address. i also read about a certain worm that researchers cracked its algorithm and used it to set a contact server. The worm collected ip addresses and keyboard strokes and dumped them in the server. The worm reveals your passwords, sites visited, what you wrote or chatted. i think the above three are quite likely leaders. -- Bored? Stop been Bored. why are u still Bored? visit my blog http://gramware.blogspot.com Get your free issue of tekniaonline, a Kenyan ICT magazine at http://tekniaonline.blogspot.com
participants (4)
-
Dennis Kioko
-
Jamal Mohamed
-
Martin Gachunga
-
Simon Mbuthia