Madshrimps Forum Madness

Madshrimps Forum Madness (https://www.madshrimps.be/vbulletin/)
-   Hardware/Software Problems, Bugs (https://www.madshrimps.be/vbulletin/f14/)
-   -   Who's sending the emails ? (https://www.madshrimps.be/vbulletin/f14/who-s-sending-emails-4640/)

Bosw8er 19th April 2004 10:19

Who's sending the emails ?
 
I get an increasing number of emails returned to my accounts with the message :
- couldn't deliver because address doesn't exist
- couldn't deliver because of virus attach

1) The addresses to whom they were send aren't in my addressbook, in none of the other users addressbooks, ... in fact no-one knows the addresses in the first place
2) The emails are not in one of users send-folder
3) All boxes on the network have the latest anti-virus updates and have been scanned twice
4) Because 2 of the bounced emails mentioned the w32 netsky virus, i ran the removal tool on all boxes ... no virus to be found
5) I changed the passwords of two accounts (which were used to send virus infected emails and then bounced)
6) I send a number of the bounced emails to skynet-abuse (i have skynet adsl) ... no solution there

... but those emails keep on coming. I presume it's quite innocent and harmless ... but still quite annoying

Any idea's how to avoid them ?

jmke 19th April 2004 10:20

Avoid them: nope.
just delete em

Quote:

Hello,

Someone who is infected with a virus has your address in his address book (or your domain), and the virus sends out fake message to the contacts, you can safely delete these messages.

More info on email spoofing can be found here:

http://www.techtv.com/screensavers/a...566233,00.html

http://www.lse.ac.uk/itservices/help...g&spoofing.htm

"Email-distributed viruses that use spoofing, such the Klez or Sobig virus, take a random name from somewhere on the infected person’s hard disk and mail themselves out as if they were from that randomly chosen address. Recipients of these viruses are therefore misled as to the address from which they were sent, and may end up complaining to, or alerting the wrong person. As a result, users of uninfected computers may be wrongly informed that they have, and have been distributing a virus. "

Kind regards,

John M

Bosw8er 19th April 2004 10:30

Best solution is then to just keep sending the bounced messages to skynet - abuse ... so maybe one day they'll track down the infected one ?

jmke 19th April 2004 10:33

very hard to trace since both sending party AND destined party can be spoofed by the virus, thereby making it impossible to track who has been infected.

BlackRabbit 19th April 2004 10:34

Sending emails to abuse won't work since the sender of the virus is "you".

I alse recieve these messages, as well as mails from angry people who recieve viri from "me".
Even recieved an email from abuse@pi.be telling me I'm infected blabla..

Problem is I have aa very public email account (datanuke) which is an easy target for searchbots..

jmke 19th April 2004 10:35

these spoofing viri are doing out at the moment, so the flow of these bounced messages will diminish as time goes by.

you got put these messages in the Spambayes filter

Bosw8er 19th April 2004 10:57

Worst problem here is some people replied with great anger to those emails ... from people that i actually know.
No matter what i tell them, they do NOT want to believe they do NOT come from me. ("yeah, yeah, but YOU send them ...")

thx for the links, i will use them in my replies

jmke 19th April 2004 11:14

I used that quoted reply for everyone @ work who inquires about these spoofed emails. some people ask the same question every other day, I reply the same thing every day :)

FreeStyler 19th April 2004 18:05

do keep sending them to abuse.

One day they'll get sick of them and they might actually do something about it.
Abd you CAN trrack the real sender of E-mail, it's somewhere in the header (part that outlook doesn't show) and it's IP based.

jmke 19th April 2004 19:15

Freestyler.. look up in-depth spoofing. and IP-spoofing.


All times are GMT +1. The time now is 01:43.

Powered by vBulletin® - Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO