Speaking of missing memos... mailing lists are not highly compatible
with HTML or some clients that like to encode list mail. The above is
what your mail looked like to some people.

I would suggest a different Step 1. Instead of killing power, simply
isolate the affected machine. This might be as simple as putting up a
firewall rule or two, if it is simply sending outgoing SMTP spam, or
for more complex issues, downing the port facing the machine in question.
Killing the power may destroy useful forensic clues about what happened
to the system, and may damage the system.

... JG

it's probably easiest (depending on the network gear of course) to
just put the lan port into an isolated VLAN. It's not the 100%
solution (some badness rm's itself once it loses connectivity to the
internets) but it'd make things simpler for the client/LEA when they
need to figure out what happened.


In article <200809240320.m8O3KIw0019735@aurora.sol.net> you write:

  Most email from Yahoo is like this. Yahoo doesn't know how
  to do quoted-printable properly. It displays ok if you
  speak mime but not if you don't. The intent of quoted-printable
  is to display ASCII nicely if you don't have a mime compliant


  RFC 2045.

   The Quoted-Printable encoding is intended to represent data that
   largely consists of octets that correspond to printable characters in
   the US-ASCII character set. It encodes the data in such a way that
   the resulting octets are unlikely to be modified by mail transport.
   If the data being encoded are mostly US-ASCII text, the encoded form
   of the data remains largely recognizable by humans. A body which is
   entirely US-ASCII may also be encoded in Quoted-Printable to ensure
   the integrity of the data should the message pass through a
   character-translating, and/or line-wrapping gateway.


    (4) (Line Breaks) A line break in a text body, represented
          as a CRLF sequence in the text canonical form, must be
          represented by a (RFC 822) line break, which is also a
          CRLF sequence, in the Quoted-Printable encoding. Since
          the canonical representation of media types other than
          text do not generally include the representation of
          line breaks as CRLF sequences, no hard line breaks
          (i.e. line breaks that are intended to be meaningful
          and to be displayed to the user) can occur in the
          quoted-printable encoding of such types. Sequences
          like "=0D", "=0A", "=0A=0D" and "=0D=0A" will routinely
          appear in non-text data represented in quoted-
          printable, of course.


Look, the people posting here who are trashing Intercage are pure security
analysts -- they
know and understand the evil that is Intercage. STOP TRYING TO ASSIST
-- you are effectively aiding and abetting the enemy.

Intercage/Atrivo hosts the malware c&c botnets that DDoS your systems and

Intercage/Atrivo hosts the spyware that compromises your users' passwords.

Intercage/Atrivo hosts the adware that slows your customers' machines.

Don't take my word for it, DO YOUR OWN RESEARCH:

You don't get called the ***American RBN*** for hosting a couple bad
machines. They
have and will continue to host much of the malware pumped out of America.

These people represent the most HIGHLY ORGANZIED CRIME you will ever
come across. Most people were afraid to speak out against them until this
recent ground swell.


Many links have been posted here that prove this already -- instead of
what customers they cut off, let them show WHAT CUSTOMERS ARE LEGIT--
because there are NONE.