Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Computer Security > Why is this URL dangerous?

Reply
Thread Tools

Why is this URL dangerous?

 
 
Franky
Guest
Posts: n/a
 
      08-13-2004
My PC says the following URL found in an email is dangerous.

http://www.ntlworld.com/inbox/pat.cu...essionid-19507

which activates

cid:031401Mfdab4$3f3dL780$73387018@57W81fa70re

I would imagine it is dangerous as my antivirus software also
detected a malicious file attachment on the same email.

But what is "cid:"? Is this the part that is dangerous or is it
the "www" section which is dangerous?

Thank you to anyone who can help me understand about this. Google
does not give me any real info when I search for "cid:".
 
Reply With Quote
 
 
 
 
Walter Schiessberg
Guest
Posts: n/a
 
      08-13-2004
Franky wrote on 13.08.2004 09:14:

> My PC says the following URL found in an email is dangerous.
>
> http://www.ntlworld.com/inbox/pat.cu...essionid-19507


Non existant, I bet.

>
> which activates
>
> cid:031401Mfdab4$3f3dL780$73387018@57W81fa70re


This decodes to "about:blank"

>
> I would imagine it is dangerous as my antivirus software also
> detected a malicious file attachment on the same email.
>
> But what is "cid:"? Is this the part that is dangerous or is it
> the "www" section which is dangerous?


No, it's the attachement.

>
> Thank you to anyone who can help me understand about this. Google
> does not give me any real info when I search for "cid:".


Google gives you 410 references for
"cid:031401Mfdab4$3f3dL780$73387018@57W81fa70r e"

No need for crossposting to four groups if you can find the answer in
two minutes by asking a search machine.

--
Walter
 
Reply With Quote
 
 
 
 
John Elsbury
Guest
Posts: n/a
 
      08-13-2004
On Fri, 13 Aug 2004 08:14:42 +0100, Franky <>
wrote:

>My PC says the following URL found in an email is dangerous.
>
> <snip malware link>
>
>which activates
>
> cid:031401Mfdab4$3f3dL780$73387018@57W81fa70re
>
>I would imagine it is dangerous as my antivirus software also
>detected a malicious file attachment on the same email.
>
>But what is "cid:"? Is this the part that is dangerous or is it
>the "www" section which is dangerous?
>
>Thank you to anyone who can help me understand about this. Google
>does not give me any real info when I search for "cid:".


Try googling for PHP exploit or PHP spyware or PHP trojan and see what
you get. PHP files are exploitable, and exploited. Also look up the
name of whatever your AV software told you it was on your AV software
vendor's website. What is probably happening is that there will be a
series of items downloaded (or attempts, as in your case, blocked by
the AV software) which will result in unwanted software being planted
on an unprotected PC.

It is not a good idea to post links in full where you know they link
to malware sites, somebody else might get caught by the same exploit.

While on this subject, now is a very good time to get your software
updated so thet the exploitable vulnerabilities in MSIE, MSOE, and
Windows are patched. All these exploits make use of holes in those
products and if you are fully patched you don't need to worry quite so
much.
Please remove "nospam" from mailto address
when replying
 
Reply With Quote
 
Franky
Guest
Posts: n/a
 
      08-13-2004
Walter Schiessberg <> wrote:

> Franky wrote on 13.08.2004 09:14:
>
>> My PC says the following URL found in an email is dangerous.
>>
>> http://www.ntlworld.com/inbox/pat.cu...essionid-19507

>
> Non existant, I bet.
>
>>
>> which activates
>>
>> cid:031401Mfdab4$3f3dL780$73387018@57W81fa70re

>
> This decodes to "about:blank"
>
>>
>> I would imagine it is dangerous as my antivirus software also
>> detected a malicious file attachment on the same email.
>>
>> But what is "cid:"? Is this the part that is dangerous or is
>> it the "www" section which is dangerous?

>
> No, it's the attachement.


The attachment was deleted long ago. When I click on the link in
the email and it launches the 'cid' thing then my Opera browser
gives me a warning and the message seems to refer to a login.

I didn't record the message but it seems to me that the link is in
some way malicious. I posted here to ask if someone could explain
it.

>> Thank you to anyone who can help me understand about this.
>> Google does not give me any real info when I search for
>> "cid:".

>
> Google gives you 410 references for
> "cid:031401Mfdab4$3f3dL780$73387018@57W81fa70r e"
>
> No need for crossposting to four groups if you can find the
> answer in two minutes by asking a search machine.
>


As I explained, I didn't get the answer from Google. And i am not
sure you have necessarily got the answer either when you say it is
because of the attachment file.
 
Reply With Quote
 
Guy
Guest
Posts: n/a
 
      08-13-2004
Franky wrote:

> I didn't record the message but it seems to me that the link is in
> some way malicious.
>



Put this into your Opera browser address bar: user:1@fake

Read the security warning... and think about it.

--
Regards,
Guy

<URL:http://guysalias.batcave.net/pgpkeys.txt> [Updated: 4/29/2004]
 
Reply With Quote
 
Richard S. Westmoreland
Guest
Posts: n/a
 
      08-24-2004
"Franky" <> wrote in message
news:954453DF7898831E75@127.0.0.1...
> My PC says the following URL found in an email is dangerous.
>
> http://www.ntlworld.com/inbox/pat.cu...essionid-19507
>
> which activates
>
> cid:031401Mfdab4$3f3dL780$73387018@57W81fa70re
>
> I would imagine it is dangerous as my antivirus software also
> detected a malicious file attachment on the same email.
>
> But what is "cid:"? Is this the part that is dangerous or is it
> the "www" section which is dangerous?
>
> Thank you to anyone who can help me understand about this. Google
> does not give me any real info when I search for "cid:".


The first "link" is just the description of the real link, which is the cid:
It tricks people into running the attachment that is included in the email.
The cid: is what is dangerous.

--
Richard S. Westmoreland
http://www.antisource.com


 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Malformed URL by using Page.Request.Url.ToString() - why? =?Utf-8?B?QXhlbCBEYWhtZW4=?= ASP .Net 3 04-18-2007 06:45 AM
why why why why why Mr. SweatyFinger ASP .Net 4 12-21-2006 01:15 PM
findcontrol("PlaceHolderPrice") why why why why why why why why why why why Mr. SweatyFinger ASP .Net 2 12-02-2006 03:46 PM
URL - substitution of a correct URL by a GUID like URL in favorites. Just D. ASP .Net Mobile 0 08-11-2004 04:26 PM
redirect URL's, return URL's, and URL Parameters Jon paugh ASP .Net 1 07-10-2004 05:29 AM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57