Right now I am pretty badly hit by the new Swen virus (formerly known as W32.Gibe). Our university mail-server doesn't yet cut out the offending attachments so I received around 200 mails this night, each around 140K in size.
I have now stopped fetchmail and set up a little script employing Mail::POP3Client that rigidly deletes anything looking like spam and Swen on the server. I've stopped worrying about false positives for now.
Swen-infected machines increment a webcounter. Hit "reload" occasionally and see the number increase.
POP3 chainsaw (Score:2)
I didn't receive a lot of Sobig crap, but this one is hitting me pretty badly.
Re:POP3 chainsaw (Score:2, Informative)
Right now I switched to manual mode. If you modify the outcommented if-conditions a little to suit your specific flavour of mails, you could run it as
yes | killmail USER PASS.If these mails continue to exist tomorrow, I'll refine the script and let it run as cronjob. I am sick of the current situation. I hope the mail-server admins quickly come up with a server-side solution.
Re:POP3 chainsaw (Score:2, Informative)
Re:POP3 chainsaw (Score:1)
I eventually solved it with a few procmail rules. The To: line of these mails always consists of words chosen randomly from a set of nine words. So I just have to check for
Re:POP3 chainsaw (Score:2)
Curious. I've not got that many of these (yet)(about 60), but I did recieve a lot of sobig crap (150100 to
/dev/nullto date, and another 100M or so before I started filtering)