Page 2 of 3 FirstFirst 123 LastLast
Results 11 to 20 of 22

Thread: weird e-mail hack

  1. #11
    Heres the info steve.milner


    X-Apparently-To: [email protected] via 66.218.78.207; Mon, 15 Dec 2003 12:38:04 -0800
    Return-Path: <[email protected]>
    Received: from 220.226.40.105 (HELO alpha) (220.226.40.105) by mta144.mail.scd.yahoo.com with SMTP; Mon, 15 Dec 2003 12:38:02 -0800
    From: [email protected]
    To: [email protected]
    MIME-Version: 1.0
    Content-type: text/plain; charset=US-ASCII
    X-Priority: 3
    Content-Length: 136

  2. #12
    AO French Antique News Whore
    Join Date
    Aug 2001
    Posts
    2,126
    You received a email from a SMTP server who was using ip address 220.226.40.105 (Who is now not responding). So it's probably a spam.

    This is a spam method who forge the email source so it's the same the destination email address.
    -Simon \"SDK\"

  3. #13
    Agreed - just common open-relay spam:

    The fact that it shows "(HELO alpha)" very much matches the common methods of using an open relay email server.

    Which as mentioned allows them to type in ANYTHING for the MAIL FROM address and they've just choosen to use the same thing as the RCPT TO line.

    RRP

  4. #14
    hi,
    The problem to : & from: [email protected] .... is fake mail..
    some websites are providing like "www.fakemailz.com"...or he will send through connecting ftp server in any of the mailserver
    get the full header & find the system ip id ...
    regards,
    lok

  5. #15
    Senior Member therenegade's Avatar
    Join Date
    Apr 2003
    Posts
    400
    you sure it isnt a forgery?I mean..forging mail's easy plus there're a lot of programs out there that allow any script kiddie to forge mail..n yup...you'll have to have a peek at the headers to find out if it's been forget or not..I seriously doubt someone's hacked your password..wouldnt it be more logical for him to change it then?

  6. #16
    Some Assembly Required ShagDevil's Avatar
    Join Date
    Nov 2002
    Location
    SC
    Posts
    718

    Lightbulb

    I'd also recommend reading up on Forged/Spoofed Email
    Use PGP/Encryption if you're really worried about people snooping around your emails.
    The object of war is not to die for your country but to make the other bastard die for his - George Patton

  7. #17
    Macht Nicht Aus moxnix's Avatar
    Join Date
    May 2002
    Location
    Huson Mt.
    Posts
    1,752
    Yes, I would say it is just spam:
    Search results for: 220.226.40.105


    OrgName: Asia Pacific Network Information Centre
    OrgID: APNIC
    Address: PO Box 2131
    City: Milton
    StateProv: QLD
    PostalCode: 4064
    Country: AU

    ReferralServer: whois://whois.apnic.net

    NetRange: 220.0.0.0 - 220.255.255.255
    CIDR: 220.0.0.0/8
    NetName: APNIC6
    NetHandle: NET-220-0-0-0-1
    Parent:
    NetType: Allocated to APNIC
    NameServer: NS1.APNIC.NET
    NameServer: NS3.APNIC.NET
    NameServer: NS.RIPE.NET
    NameServer: RS2.ARIN.NET
    Comment: This IP address range is not registered in the ARIN database.
    Comment: For details, refer to the APNIC Whois Database via
    Comment: WHOIS.APNIC.NET or http://www.apnic.net/apnic-bin/whois2.pl
    Comment: ** IMPORTANT NOTE: APNIC is the Regional Internet Registry
    Comment: for the Asia Pacific region. APNIC does not operate networks
    Comment: using this IP address range and is not able to investigate
    Comment: spam or abuse reports relating to these addresses. For more
    Comment: help, refer to http://www.apnic.net/info/faq/abuse
    Comment:
    RegDate:
    Updated: 2002-09-11

    OrgTechHandle: AWC12-ARIN
    OrgTechName: APNIC Whois Contact
    OrgTechPhone: +61 7 3858 3100
    OrgTechEmail: [email protected]

    # ARIN WHOIS database, last updated 2003-12-26 19:15
    # Enter ? for additional hints on searching ARIN's WHOIS database.


    \"Life should NOT be a journey to the grave with the intention of arriving safely in an attractive and well preserved body, but rather to skid in sideways, Champagne in one hand - strawberries in the other, body thoroughly used up, totally worn out and screaming WOO HOO - What a Ride!\"
    Author Unknown

  8. #18
    I made a newsletter program and I used the "hidden cc" option to post mail to a list of persons. That's exactly what it's doing: The customer receives an email with the same From and To. So I don't think you should be afraid about it.

  9. #19
    Junior Member
    Join Date
    Dec 2003
    Posts
    11
    hehehe I forgot how... but there's a way to track the mofo down somewhere through DOS I thinks.. =/
    \"What if the only person who could make you happy, made you cry?\"

  10. #20
    HeadShot Master N1nja Cybr1d's Avatar
    Join Date
    Jul 2003
    Location
    Boston, MA
    Posts
    1,840
    lol, telnet, whois

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •