01 July 2005

Composite Block List

Welcome, this is my first post of my first blog. I’m not quite advance in English, so I put posting mostly in Bahasa Indonesia & sometime in English :p I hope to have a lot of stories to share. Thanks for Google for hosting this blog.

In recent days my local network could not send out any email, I wondered and checked everything worked well and then I trace the mail delivery report system. Something went wrong, in one of email client program displayed error massage: “your IP is listed in Composite Block List (CBL)” Never heard before, but the massages suggested me to visit http://cbl.abuseat.org for detail. The CBL takes its source data from very large spamtraps.

Finally I found that something out there, are monitoring and told the mail-server to block every mail from my network cause it’s sending malicious or hostile massages that could also be spam massages with virus attached. I didn’t believe to see that some computers in my network are really sending those massages.

A virus named “Sober I” was responsible for all that malicious spam massages. “Sober I” is a smart virus infected windows based machine from the internet. Any computer that infected should automatically sending lot of illegal spam massages contain of viruses in two different languages: Germany & English.

I might ignore that virus is active in my LAN but the system was blocked because of sending illegal or spam massage not because of the virus. Thank, finally I found some virus are active in my network and I then should try cleaning them just away. The virus is so smart but defense is good too, because virus could not take action even if it was active. Is that also called security?