Networking Forums

Networking Forums > Computer Networking > Broadband > Spam - FROM same as my address

Reply
Thread Tools Display Modes

Spam - FROM same as my address

 
 
Terry Pinnell
Guest
Posts: n/a

 
      05-15-2004, 08:29 AM
Viewing my email this morning I see one message that MailWasher has
marked as from a Friend has my correct address as both the To *and
From addresses. Is that a common spam technique?


Its full header is:
====================
Return-Path: <(E-Mail Removed)>
X-Envelope-To: (E-Mail Removed)
Delivered-To: (E-Mail Removed)
Received: from pcp03933018pcs.sthind01.mo.comcast.net
(pcp03933018pcs.sthind01.mo.comcast.net [68.34.139.159])
by gophers.systems.pipex.net (Postfix) with SMTP id 495F5E000096
for <(E-Mail Removed)>; Fri, 14 May 2004 23:40:43 +0100
(BST)
Received: from 235.168.30.88 by 68.34.139.159; Fri, 14 May 2004
23:38:48 -0300
Message-ID: <(E-Mail Removed)>
From: "(E-Mail Removed)" <(E-Mail Removed)>
To: "(E-Mail Removed)" <(E-Mail Removed)>
Subject: Joseph
MIME-Version: 1.0
Content-type: text
Date: Fri, 14 May 2004 23:40:43 +0100 (BST)



http://puppet.xc4xzzd.com/ti/#statutory

off
http://stopgap.xc4xzzd.com/b.html#wrestle

Joseph



----0537831089286035--
====================

Anyone know what it is and where it comes from please?
 
Reply With Quote
 
 
 
 
Tiscali Tim
Guest
Posts: n/a

 
      05-15-2004, 08:40 AM
In an earlier contribution to this discussion,
Terry Pinnell <(E-Mail Removed)> wrote:

> Viewing my email this morning I see one message that MailWasher has
> marked as from a Friend has my correct address as both the To *and
> From addresses. Is that a common spam technique?
>
>
> Its full header is:
> ====================
> Return-Path: <(E-Mail Removed)>
> X-Envelope-To: (E-Mail Removed)
> Delivered-To: (E-Mail Removed)
> Received: from pcp03933018pcs.sthind01.mo.comcast.net
> (pcp03933018pcs.sthind01.mo.comcast.net [68.34.139.159])
> by gophers.systems.pipex.net (Postfix) with SMTP id 495F5E000096
> for <(E-Mail Removed)>; Fri, 14 May 2004 23:40:43 +0100
> (BST)
> Received: from 235.168.30.88 by 68.34.139.159; Fri, 14 May 2004
> 23:38:48 -0300
> Message-ID: <(E-Mail Removed)>
> From: "(E-Mail Removed)" <(E-Mail Removed)>
> To: "(E-Mail Removed)" <(E-Mail Removed)>
> Subject: Joseph
> MIME-Version: 1.0
> Content-type: text
> Date: Fri, 14 May 2004 23:40:43 +0100 (BST)
>
>
>
> http://puppet.xc4xzzd.com/ti/#statutory
>
> off
> http://stopgap.xc4xzzd.com/b.html#wrestle
>
> Joseph
>
>
>
> ----0537831089286035--
> ====================
>
> Anyone know what it is and where it comes from please?



Don't know the answer - but you can expect lots more spam now that you have
posted what appears to be your *real* email address so many times in this
message!
--
Cheers,
Tim
______
Please reply to newsgroup. Reply address is Black Hole!


 
Reply With Quote
 
Colin Wilson
Guest
Posts: n/a

 
      05-15-2004, 09:26 AM
> Viewing my email this morning I see one message that MailWasher has
> marked as from a Friend has my correct address as both the To *and
> From addresses. Is that a common spam technique?


Yes - very. Your email addresses may well be in the address book of
another compromised machine hence they had both to work from.

> Anyone know what it is and where it comes from please?


> Received: from pcp03933018pcs.sthind01.mo.comcast.net
> (pcp03933018pcs.sthind01.mo.comcast.net [68.34.139.159])


....might give you a hint... it is probably a trojanised machine run by a
complete newbie on cable. See www.theregister.co.uk which had an article
on methods used by spammers, and how anti-spammers are infiltrating their
groups to get inside information on the latest methods.

If you want some filters for mailwasher, try www.phoenixbbs.co.uk - i`ve
got a fairly recent filter list available with annotated notes on where
to edit etc. to customise them for your system.

--
Please add "[newsgroup]" in the subject of any personal replies via email
--- My new email address has "ngspamtrap" & @btinternet.com in it ;-) ---
 
Reply With Quote
 
Gordon Henderson
Guest
Posts: n/a

 
      05-15-2004, 09:30 AM
In article <(E-Mail Removed)>,
Terry Pinnell <(E-Mail Removed)> wrote:
>Viewing my email this morning I see one message that MailWasher has
>marked as from a Friend has my correct address as both the To *and
>From addresses. Is that a common spam technique?


Yes. Think yourself lucky you only got one message. My email address
was recently hijacked by spammers and I recieved several thousand bounce
replies. Fortunataly I have the means to deal with it, but I know others
who haven't been so lucky and have had to abandon that address because
they couldn't reasonably clear their incoming mail via dial-up and POP.

Gordon
 
Reply With Quote
 
Gareth :-\) voom
Guest
Posts: n/a

 
      05-15-2004, 09:37 AM
"Terry Pinnell" <(E-Mail Removed)> wrote in message

> Viewing my email this morning I see one message that MailWasher has
> marked as from a Friend has my correct address as both the To *and
> From addresses. Is that a common spam technique?<


Yes I get tons of it....word of advice...nver post your real email address
in a newsgroup. Spam programs harvest the email addresses from newsgroups
which means your email address will now get picked up by more spammers.

When posting, either use a junk email address like hotmail or modify the
address with a nospam trap.


 
Reply With Quote
 
Java Jive
Guest
Posts: n/a

 
      05-16-2004, 09:43 AM
First, as as already been said, never put your real email in a ng post!

As a public service here is how to deal with this and similar spam. The more
victims who actively pursue spammers, the less worthwhile spamming becomes.

In this case, the important bits of the header appear to be ...

Received: from pcp03933018pcs.sthind01.mo.comcast.net
(pcp03933018pcs.sthind01.mo.comcast.net [68.34.139.159])

.... and ...

Received: from 235.168.30.88 by 68.34.139.159; Fri, 14 May 2004
23:38:48 -0300

Ultimately, the goal is to look up an abuse contact for the source here ...
http://www.abuse.net/lookup.phtml
.... but to do that we need a domain name and we only have an IP.

So first we look up the domain for 235.168.30.88 here ...
http://www.whois.sc/

http://www.whois.sc/235.168.30.88, gives:

name type result
235.IN-ADDR.ARPA.
SOA source=dot.ep.net.; responsible person=(E-Mail Removed).



As indicated by the WhoIs page, the abuse contact for ep.net,
http://www.abuse.net/lookup.phtml?DOMAIN=ep.net, is (E-Mail Removed), ie:
unhelpful default, so next we do a tracert from a DOS box to see who is
hosting ep.net:

C:\TEMP>tracert ep.net

Tracing route to ep.net [198.32.6.68]
over a maximum of 30 hops:

[snip]

8 411 ms 430 ms 471 ms so-7-0-0.cr1.dca2.us.above.net
[64.125.31.186]
9 561 ms 521 ms 631 ms sl-gw19-rly-3-0.sprintlink.net
[144.232.247.85]
10 180 ms 210 ms 291 ms sl-bb23-rly-3-1.sprintlink.net
[144.232.14.41]
11 90 ms 110 ms 120 ms sl-bb27-rly-10-0.sprintlink.net
[144.232.14.142]
12 * 200 ms 240 ms sl-bb22-rly-10-0.sprintlink.net
[144.232.14.177]
13 360 ms 401 ms 521 ms sl-bb22-sj-10-0.sprintlink.net
[144.232.20.186]
14 551 ms 591 ms 641 ms sl-bb25-sj-12-0.sprintlink.net
[144.232.3.210]
15 571 ms 711 ms 681 ms sl-bb23-ana-6-0.sprintlink.net
[144.232.20.158]
16 741 ms 752 ms 831 ms sl-gw25-ana-0-0.sprintlink.net
[144.232.1.114]
17 671 ms 801 ms 871 ms sl-epnet-1-0.sprintlink.net [160.81.102.134]
18 500 ms 631 ms 691 ms vacation.karoshi.com [198.32.6.68]

Trace complete.

Now we work backwards up the list until we get a real abuse contact:

http://www.abuse.net/lookup.phtml?DOMAIN=karoshi.com,
(E-Mail Removed), default, no good.

http://www.abuse.net/lookup.phtml?DOMAIN=sprintlink.net, (E-Mail Removed),
there's your abuse contact address for the source machine of that particular
email.

But that's only half the story, there is also the linked website:
xc4xzzd.com, which is presumably responsible for originating the spamming,
possibly by proxy through captured machines.

Again we get the default for an abuse contact, so we're going to have work
out this one as well. WhoIs for this domain,
http://www.whois.sc/xc4xzzd.com, gives

IP Address: 61.233.138.58 (ARIN & RIPE IP search)
IP Location: China - China Railway Telecommunications Center

Someone is probably abusing their work facilities there.

So again we use tracert to see who is hosting China Railways / xc4xzzd.com.

C:\TEMP>tracert xc4xzzd.com

Tracing route to xc4xzzd.com [61.233.138.58]
over a maximum of 30 hops:

[snip]

8 471 ms 501 ms 511 ms so-7-0-0.cr1.dca2.us.above.net
[64.125.31.186]
9 701 ms 661 ms 711 ms pos0-0.pr1.atl4.us.above.net [64.125.28.230]
10 561 ms 661 ms 731 ms pos12-0.er1.atl4.us.above.net
[64.125.30.233]
11 651 ms 620 ms 471 ms so-3-3-0.mpr2.iah1.us.above.net
[64.125.29.66]
12 701 ms 661 ms 772 ms so-0-0-0.mpr1.iah1.us.above.net
[64.125.31.61]
13 631 ms 681 ms 761 ms so-5-1-0.mpr2.lax9.us.above.net
[64.125.29.97]
14 621 ms 400 ms 421 ms above-oc12.china-telecom.net [64.125.12.126]
15 660 ms 732 ms 741 ms 202.97.49.65

[snip]

Trace complete.

So it's fairly clear that the linked website is being hosted by
china-telecom.net. However,
http://www.abuse.net/lookup.phtml?DO...na-telecom.net, gives:

(E-Mail Removed) (for china-telecom.net)
(E-Mail Removed) (for china-telecom.net)

ie: a default and a second contact within abuse.net, which suggests that
they are either having trouble with that domain, or else abuse complaints
have to go through a particular protocol which they handle directly. Anyway,
despite this, address your complaint to both these contacts, because in this
case, it's all you can do.

I would suggest your complaint is worded something along the lines of: ...

To: (E-Mail Removed), (E-Mail Removed),
(E-Mail Removed)

Subject: SPAM - <cut'n'paste the spam mail subject here>

The email enclosed is unsolicited SPAM.

Please take appropriate action against the mail source apparently posting
through ep.net [235.168.30.88]

Please take appropriate action against the linked website, xc4xzzd.com,
apparently hosted through china-telecom.net [195.149.20.137].

Please share information concerning these sources' abuse with other ISPs and
NSPs

Original Header
===============
<cut'n'paste the spam mail header here>


Original Post
=============
<cut'n'paste the spam mail body here>





"Terry Pinnell" <belatedly removed all these for spam trap reasons> wrote in
message news:(E-Mail Removed)...
> Viewing my email this morning I see one message that MailWasher has
> marked as from a Friend has my correct address as both the To *and
> From addresses. Is that a common spam technique?
>
>
> Its full header is:
> ====================
> Return-Path: <>
> X-Envelope-To:
> Delivered-To:
> Received: from pcp03933018pcs.sthind01.mo.comcast.net
> (pcp03933018pcs.sthind01.mo.comcast.net [68.34.139.159])
> by gophers.systems.pipex.net (Postfix) with SMTP id 495F5E000096
> for <t>; Fri, 14 May 2004 23:40:43 +0100
> (BST)
> Received: from 235.168.30.88 by 68.34.139.159; Fri, 14 May 2004
> 23:38:48 -0300
> Message-ID: <x7fRY3UpC3PeN2RGGC etc>
> From: "" <>
> To: "" <>
> Subject: Joseph
> MIME-Version: 1.0
> Content-type: text
> Date: Fri, 14 May 2004 23:40:43 +0100 (BST)
>
>
>
> http://puppet.xc4xzzd.com/ti/#statutory
>
> off
> http://stopgap.xc4xzzd.com/b.html#wrestle
>
> Joseph
>
>
>
> ----0537831089286035--
> ====================
>
> Anyone know what it is and where it comes from please?



---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.683 / Virus Database: 445 - Release Date: 12/05/2004


 
Reply With Quote
 
Terry Pinnell
Guest
Posts: n/a

 
      05-16-2004, 09:54 AM
"Gareth :-\) voom" <(E-Mail Removed)> wrote:

>"Terry Pinnell" <(E-Mail Removed)> wrote in message
>
>> Viewing my email this morning I see one message that MailWasher has
>> marked as from a Friend has my correct address as both the To *and
>> From addresses. Is that a common spam technique?<

>
>Yes I get tons of it....word of advice...nver post your real email address
>in a newsgroup. Spam programs harvest the email addresses from newsgroups
>which means your email address will now get picked up by more spammers.
>
>When posting, either use a junk email address like hotmail or modify the
>address with a nospam trap.
>

Thanks for all the helpful replies. Will folow up those suggestions.
As for using real email in NGs - I'm a bit apprehensive about simply
changing that in the usual way (e.g. inserting 'DELETETHIS' or
whatever), as I'm sure I had some downside consequence from that with
either MailWasher or my APN news service. (I apprecaite that's
annoyingly vague. I was experimenting with several things at the time,
shortly after getting BT Broadband, and trying to recover email and
news services, which were not part of the deal.) So I reverted to my
correct email address.

--
Terry Pinnell
Hobbyist, West Sussex, UK

 
Reply With Quote
 
Steven Campbell
Guest
Posts: n/a

 
      05-16-2004, 10:32 AM
> Thanks for all the helpful replies. Will folow up those suggestions.
> As for using real email in NGs - I'm a bit apprehensive about simply
> changing that in the usual way (e.g. inserting 'DELETETHIS' or
> whatever), as I'm sure I had some downside consequence from that with
> either MailWasher or my APN news service. (I apprecaite that's
> annoyingly vague. I was experimenting with several things at the time,
> shortly after getting BT Broadband, and trying to recover email and
> news services, which were not part of the deal.) So I reverted to my
> correct email address.



Terry, I don't know what news reader you are using but in OE all you need
to change is your email address in your News account. This will only change
the email that is displayed in Newsgroups, it won't change your actual email
adress you use for sending personal emails.

Tools/Accounts/News/Properties.

Steven.



 
Reply With Quote
 
Terry Pinnell
Guest
Posts: n/a

 
      05-21-2004, 09:17 AM
"Steven Campbell" <(E-Mail Removed)> wrote:

>> Thanks for all the helpful replies. Will folow up those suggestions.
>> As for using real email in NGs - I'm a bit apprehensive about simply
>> changing that in the usual way (e.g. inserting 'DELETETHIS' or
>> whatever), as I'm sure I had some downside consequence from that with
>> either MailWasher or my APN news service. (I apprecaite that's
>> annoyingly vague. I was experimenting with several things at the time,
>> shortly after getting BT Broadband, and trying to recover email and
>> news services, which were not part of the deal.) So I reverted to my
>> correct email address.

>
>
>Terry, I don't know what news reader you are using but in OE all you need
>to change is your email address in your News account. This will only change
>the email that is displayed in Newsgroups, it won't change your actual email
>adress you use for sending personal emails.
>
>Tools/Accounts/News/Properties.
>
>Steven.


Thanks to all for helpful replies.

But I'm plainly still missing something very obvious here, and would
appreciate a little further help please.

As per my separate post, I recently altered my 'From' email address in
Agent>Options to
(E-Mail Removed)
in a belated attempt to reduce spam. To answer my own question in that
spearate post, it now seesm certain that all emails I've sent since
making that change have vanished. The usual 'sending email' message
has appeared in Agent's staus bar, and I've never received any later
indication of failure. (Perhaps I did, and MailWasher filtered them
out?)

So, can anyone here tell me how other Agent users set up their
configuration so that they can use a 'munged' email address please?

--
Terry, West Sussex, UK


 
Reply With Quote
 
Terry Pinnell
Guest
Posts: n/a

 
      05-21-2004, 09:48 AM
Terry Pinnell <(E-Mail Removed)> wrote:



>So, can anyone here tell me how other Agent users set up their
>configuration so that they can use a 'munged' email address please?


Now sorted via Agent NG thanks.

--
Terry, West Sussex, UK

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
What is Anti-Spam Filter.(thunderbird spam filter) zak07000 Broadband 0 03-27-2008 03:41 PM
spam please throwawayaccount0001@gmail.com Broadband 3 12-29-2007 06:41 PM
Spam Paul Hanson Broadband 45 02-09-2006 09:24 AM
Spam Mel Broadband 6 05-25-2004 11:18 PM
[spam] 2.4GHz 18dBi sector for sale [/spam] Marcin £ukasik Wireless Internet 0 02-28-2004 11:44 AM



1 2 3 4 5 6 7 8 9 10 11