 |
 |
 |
 |
| Security and Privacy Sadly, malware, spyware, hackers and privacy threats abound in today's world. Let's be paranoid and secure our penguins, and slam the doors on privacy exploits. |

16th October 2009, 10:28 AM
|
 |
Techno-Womble
|
|
Join Date: Aug 2006
Location: Gloucestershire, U.K.
Posts: 1,792

|
|
|
Spoofed e-mail address
Not sure if this really belongs in ' Security ', as I'll explain, but I thought it was the best place to get an answer.
I'm pretty sure my F11 box hasn't been hacked - I'm behind a modem router with firewall and SElinux enabled by default - but checking my mail this morning I noticed several ' delivery failures ' ( allegedly ) from hotmail referring to mail I hadn't sent. When I checked the spam folder for the on-line side of my mail account there were more failure notices.
Two points that may be relevant, one is the recent Hotmail exploit, the other is that this only occurred with the address I use for railway matters, and some people cc to everybody, so it's odds on that address is on a good few computers.
On one occassion when I checked my spam folder on-line I found spam which claimed to be from myself, so I know the ' send ' address can be spoofed, is this the explanation, or is it a new kind of attack linked to the Hotmail exploit?
__________________
To get the right answer, one must first ask the right question!
Desktop #1 F18
Desktop #2 Mint 14
Laptop: Macpup 529
Netbook: Debian ARM
|

16th October 2009, 10:48 AM
|
 |
Registered User
|
|
Join Date: Aug 2006
Location: /dev/realm/{Abba,Carpenters,...stage}
Posts: 3,286

|
|
I would'n worry very much about it. My Spam section is full of emails sent by "me" to me  (thanks to my "Everybody's using Windows"-type contacts  )
|

16th October 2009, 11:11 AM
|
|
Clueless in a Cuckooland
|
|
Join Date: Mar 2006
Location: Here now, elsewhere tomorrow.
Posts: 3,923

|
|
|
Spammer has simply used your address as sender in their latest batch, and dumb mail servers then return error messages to you. Another possibility is you're lucky receiver of "Mail server error spam" where spammer sends messages looking like legitimate mail server error message which are normally let through by all spam filters and more likely to be opened and read by the recipient (you).
|

16th October 2009, 11:15 AM
|
 |
Retired Community Manager -- Banned from Texas by popular demand.
|
|
Join Date: Sep 2007
Location: NYC
Posts: 8,142

|
|
It's called backscatter if you want to google it further. I have a dated page on postfix that deals with one way to handle it if you run postfix.
http://home.roadrunner.com/~computer...u/postfix.html
It's towards the end of the article, just search for the word backscatter on the page.
__________________
--
http://home.roadrunner.com/~computertaijutsu
Do NOT PM forum members with requests for technical support. Ask your questions on the forum.
"I don't know why there is the constant push to break any semblance of compatibility" --anon
|

16th October 2009, 11:31 AM
|
 |
Techno-Womble
|
|
Join Date: Aug 2006
Location: Gloucestershire, U.K.
Posts: 1,792

|
|
Nokia, Pete,
Thanks for confirming my suspicions, I wasn't sure if failure messages could be spoofed, but I suppose it's similar to phishing, get a genuine copy and edit.
The ' cc everyone ' procedure is a real pain when it's used for all mail, regardless of relevance, and even more so when some recipients don't have the first idea about security.
__________________
To get the right answer, one must first ask the right question!
Desktop #1 F18
Desktop #2 Mint 14
Laptop: Macpup 529
Netbook: Debian ARM
|

16th October 2009, 11:48 AM
|
 |
Retired Community Manager -- Banned from Texas by popular demand.
|
|
Join Date: Sep 2007
Location: NYC
Posts: 8,142

|
|
|
Unfortunately, far too many of our friends and relations will, meaning well, pass on the latest joke, virus warning (seen on MSN!!!!! It will eat your refrigerator!!!! SEND THIS TO EVERYONE!!!), cute cat picture, or the thing to be passed to 5 people because it really works, I always send a very polite (as they are friends and family) note explaining that they've now given hundreds of email addresses to lots of people who shouldn't have them.
Hopefully, at least some of them think about it next time, and start using bcc.
__________________
--
http://home.roadrunner.com/~computertaijutsu
Do NOT PM forum members with requests for technical support. Ask your questions on the forum.
"I don't know why there is the constant push to break any semblance of compatibility" --anon
|

16th October 2009, 04:00 PM
|
 |
Techno-Womble
|
|
Join Date: Aug 2006
Location: Gloucestershire, U.K.
Posts: 1,792

|
|
Quote:
Originally Posted by scottro
Unfortunately, far too many of our friends and relations will, meaning well, pass on the latest joke, virus warning (seen on MSN!!!!! It will eat your refrigerator!!!! SEND THIS TO EVERYONE!!!), cute cat picture, or the thing to be passed to 5 people because it really works, I always send a very polite (as they are friends and family) note explaining that they've now given hundreds of email addresses to lots of people who shouldn't have them.
Hopefully, at least some of them think about it next time, and start using bcc.
|
Even worse, I get some forwarded mail with two or even three layers of 'cc' s. Must work out how to strip those off ( in Thunderbird ) if I need to forward anything. Back in the old ( snailmail ) days would they have left their address book / filofax lying around for everyone to read?
__________________
To get the right answer, one must first ask the right question!
Desktop #1 F18
Desktop #2 Mint 14
Laptop: Macpup 529
Netbook: Debian ARM
|

16th October 2009, 09:16 PM
|
 |
Retired Community Manager -- Banned from Texas by popular demand.
|
|
Join Date: Sep 2007
Location: NYC
Posts: 8,142

|
|
|
Yeah, that's what I meant, actually. Their cc's which are top posted over someone else's cc's, basically spammer's delight.
__________________
--
http://home.roadrunner.com/~computertaijutsu
Do NOT PM forum members with requests for technical support. Ask your questions on the forum.
"I don't know why there is the constant push to break any semblance of compatibility" --anon
|

17th October 2009, 02:39 AM
|
|
Registered User
|
|
Join Date: Aug 2006
Location: Circleville, Ohio
Age: 65
Posts: 473

|
|
|
Click> Drag>copy and post to new compose then send as new bcc email only takes a few minutes and stop the spread of email addresses. That's what I do on multi layers, otherwise when you forward Hi-lite and delete all email addresses.
__________________
Dan
Registered Linux user #432525
Linux Box # 337563
|

17th October 2009, 08:50 AM
|
 |
Registered User
|
|
Join Date: Aug 2006
Location: /dev/realm/{Abba,Carpenters,...stage}
Posts: 3,286

|
|
|
Perhaps you're confusing cc with bcc (blind cc) ?
|

17th October 2009, 09:53 AM
|
 |
Techno-Womble
|
|
Join Date: Aug 2006
Location: Gloucestershire, U.K.
Posts: 1,792

|
|
|
As far as I'm aware bcc mail will show in your mailbox as if it was only sent to you, while cc will list everyone it was sent to. No exaggeration, one general circulation I received had 17 lines of addresses in clear! I'm certainly going to follow scottro's advice in post #6 and have a polite word with friends and relations who cc to all and sundry,. I'll also have a diplomatic word with my railway colleagues about using bcc, after all, all it needs is a ' copied to... ' line with their real names in the body of text if someone really needs to know who else has received a copy.
__________________
To get the right answer, one must first ask the right question!
Desktop #1 F18
Desktop #2 Mint 14
Laptop: Macpup 529
Netbook: Debian ARM
|

18th October 2009, 12:59 PM
|
 |
Retired Again - Administrator
|
|
Join Date: Nov 2007
Location: Reality
Posts: 3,034

|
|
Quote:
Originally Posted by scottro
... cute cat picture ...
|
But who can resist a cute cat picture? LOLCAT spam is coming, be warned ....
I once had a case at work where someone outside the work network spoofed abusive e-mails from my address to people in my workgroup. It was easy to spot, though.
__________________
.
Marching to the beat of his own conundrum.
|

18th October 2009, 11:47 PM
|
|
Registered User
|
|
Join Date: Nov 2006
Location: South Carolina
Posts: 798

|
|
Quote:
Originally Posted by scottro
It's called backscatter if you want to google it further. I have a dated page on postfix that deals with one way to handle it if you run postfix.
|
Cool, new word of the day, I read up on it from your link. Good stuff.
|

18th October 2009, 11:58 PM
|
 |
Retired Community Manager -- Banned from Texas by popular demand.
|
|
Join Date: Sep 2007
Location: NYC
Posts: 8,142

|
|
|
Glad you found it useful. Thanks for letting me know.
__________________
--
http://home.roadrunner.com/~computertaijutsu
Do NOT PM forum members with requests for technical support. Ask your questions on the forum.
"I don't know why there is the constant push to break any semblance of compatibility" --anon
|
| Thread Tools |
Search this Thread |
|
|
|
| Display Modes |
Linear Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
Current GMT-time: 19:08 (Tuesday, 21-05-2013)
|
|
 |
 |
 |
 |
|
|