From: Gene H. <ghe...@wd...> - 2014-11-11 06:09:29
|
Greetings; Using a fetchmail thats only a couple months old, built from your tarball, I just had to set, from a restart on the command line giving it the --bad-header accept option in order to clear and retrieve an obviously C&C message from a bot controller, or something similar. The header really was bad: From gene Tue Nov 11 00:37:56 2014 Return-Path: <ad...@bh...> Delivered-To: ghe...@wd... Received: from mail.wdtv.com [66.118.69.84] by coyote.coyote.den with POP3 (fetchmail-6.3.26) for <gene@localhost> (single-drop); Tue, 11 Nov 2014 00:37:56 -0500 (EST) Received: (qmail 9141 invoked by uid 508); 23 Oct 2014 14:44:53 -0400 Received: from empireland.net (74.208.106.93) by mail.wdtv.com with AES256-SHA encrypted SMTP; 23 Oct 2014 14:44:53 -0400 Received: from nx ([218.109.100.99]) (authenticated user ad...@bh...) by empireland.net (Kerio Connect 7.1.2); Thu, 23 Oct 2014 12:42:33 -0600 X-procmail: user=gene »ú·¿»·¾³·¨¹æ Message-ID: <201...@bh...> From: =?utf-8?B?6ZW/5a2Z5aWz5aOr?= <ad...@bh...> To: <hua...@hu...> Subject: =?utf-8?B?56Gu6K6k5Ye977yb6ZW/5a2Z5aWz5aOr?= Date: Fri, 24 Oct 2014 02:42:28 +0800 MIME-Version: 1.0 Content-Type: text/html; charset="utf-8" Content-Transfer-Encoding: base64 X-mailer: Aqzn 9 Followed by about 23.5kb of what looked to be base64 encoded crap. Image,virus, c&c, I have no clue. Does anything in that look familiar to you folks? I haven't cleaned it up. Thanks. Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) Genes Web page <http://geneslinuxbox.net:6309/gene> US V Castleman, SCOTUS, Mar 2014 is grounds for Impeaching SCOTUS |