On Thu, 4 Sep 2003, Glenn Darwin wrote: > Winship wrote: > >But SoBig doesn't spoof subscription email, does it? It just spoofs email > >addresses, with its own message, which won't generate a subscribe > >confirm message. Right? > > Wrong... I'm getting hit by one machine on bellsouth.net that is > sending subscribe messages every day from different e-mail addresses. I > added the .dd &MAILHEADER to the ADDREQ1 template to make sure it was a > real request. I also sent the message with complete headers to > [log in to unmask] and got no response from them and it is still > happening.... I'm not denying that you may be getting some nasties of the type you describe. I only question whether they are Sobig nasties. All of the SoBig items I have seen so far contain only the virus itself and maybe a "See attachment" line (itself an attachment). *I* have not seen any SoBig items, which I can verify as such, which contain anything which would generate a subscription confirm message from LISTSERV. I don't question that you are getting some nasties, but are you quite certain that what you describe is SoBig? Douglas Winship [log in to unmask]