Greenguy's Board


Go Back   Greenguy's Board > General Business Knowledge
Register FAQ Calendar Search Today's Posts Mark Forums Read

Reply
 
Thread Tools Search this Thread Rate Thread Display Modes
Old 2004-03-03, 01:37 PM   #1
soggy
If something goes wrong at the plant, blame the guy who can't speak English
 
soggy's Avatar
 
Join Date: Apr 2003
Location: Florida Panhandle
Posts: 304
Help soggy please

I am getting some returned un-deliverable email back that appears to someone useing my domain-names! I do not spam email so i think it is someone using my email address as the sender. I host with conepuppy and have many sites with him. Is this a scam and what should I do about it?

TIA

soggy
soggy is offline   Reply With Quote
Old 2004-03-03, 01:57 PM   #2
Surfn
If you don’t take a chance the Angels won’t dance
 
Surfn's Avatar
 
Join Date: Aug 2003
Location: Earth on occasion
Posts: 8,812
Send a message via ICQ to Surfn
I get tons of that in my spam filters I just delete it.
__________________

Surfn's Links Are you a partner?

Surfn is offline   Reply With Quote
Old 2004-03-03, 03:09 PM   #3
Verbal
Verbal prefers 56K
 
Verbal's Avatar
 
Join Date: Sep 2003
Location: Chicago, IL
Posts: 563
Send a message via ICQ to Verbal
Hi soggy,

Could just be spam, but it possibly could be what is known as a "Joe Job", which is much more serious.

"Essentially, a Joe Job is a very crude form of identity theft. Your email address is used as the "sender's address" in most cases, and your Website URL is advertised, but an especially diligent and vicious attacker may even use your name in the signature of the message. The email will not only be sent to thousands, hundreds of thousands, or millions of addresses, but it will be sent multiple times -- possibly dozens or hundreds -- to each recipient before the attack ends.

You will first become aware that your site is the victim of a Joe Job by receiving a few bounces when you check your email."....


More info HERE
__________________
Verbal
Verbal is offline   Reply With Quote
Old 2004-03-03, 05:02 PM   #4
DangerDave
Bonged
 
DangerDave's Avatar
 
Join Date: Mar 2003
Location: BrisVegas, AUSTRALIA
Posts: 4,882
Soggy,

Happens to me regularly..

Let your host and your ISP know that it isnt you.. and it should stop in a while, as the losers pick someone else to fuk with...

DD
__________________
Old Dollars >>>> Now with over 90 Hosted Free Sites <<<<
DangerDave.com.au - Adult Links to Free Porn
DangerDave is offline   Reply With Quote
Old 2004-03-03, 05:44 PM   #5
soggy
If something goes wrong at the plant, blame the guy who can't speak English
 
soggy's Avatar
 
Join Date: Apr 2003
Location: Florida Panhandle
Posts: 304
kinda weird I just got a phone call from someone saying they bought a computer from me on the internet and had my name and all.

thing is I havent sold no computer on the net! I think someone is up to no good.

soggy
soggy is offline   Reply With Quote
Old 2004-03-03, 08:57 PM   #6
soggy
If something goes wrong at the plant, blame the guy who can't speak English
 
soggy's Avatar
 
Join Date: Apr 2003
Location: Florida Panhandle
Posts: 304
Im getting more returned emails now... some say this jackass was sending out viruses. God I hate spammers I have alerted Chris @ cyberwurx about it. Not sure what else I can do?
soggy is offline   Reply With Quote
Old 2004-03-03, 09:15 PM   #7
Surfn
If you don’t take a chance the Angels won’t dance
 
Surfn's Avatar
 
Join Date: Aug 2003
Location: Earth on occasion
Posts: 8,812
Send a message via ICQ to Surfn
Some days I have hundreds some days less than a dozen. The ones I find really amusing are the ones from spammer@cyberwurx.com since I never set up my email with conepuppy. lol
__________________

Surfn's Links Are you a partner?

Surfn is offline   Reply With Quote
Old 2004-03-03, 09:45 PM   #8
Surfn
If you don’t take a chance the Angels won’t dance
 
Surfn's Avatar
 
Join Date: Aug 2003
Location: Earth on occasion
Posts: 8,812
Send a message via ICQ to Surfn
I just finished my hourly spam folder delete and this is a prime example:

Dear user of "Smutbandit.com" mailing system,

Our antivirus software has detected a large ammount of viruses
outgoing
from your email account, you may use our free anti-virus tool to
clean up
your computer software.

For details see the attached file.

Kind regards,
The Smutbandit.com team
http://www.smutbandit.com

I need to send myself an email right? lol I'm the only person using that domain email.
__________________

Surfn's Links Are you a partner?

Surfn is offline   Reply With Quote
Old 2004-03-04, 12:57 AM   #9
Bill
Selling porn allows me to stay in a constant state of Bliss - ain't that a trip!
 
Join Date: Apr 2003
Posts: 3,914
Surfn, that's the same text that was in the spoof trap that I suspected was meant to install a backdoor, I mentioned it in another thread.

It had an 18k attachment. The smallest viruses I've heard of (not that I'm some great expert) are about 30k, but attack tools can have smaller payloads, as I understand it.

soggy, if you have your email address openly listed on your pages, another surfer with a virus surfing your pages will get those pages in his cache, and the virus strips emails from the cache and mails copies of itself to eveyone else with your email as the sender. When those virus laden emails bounce from bad addresses they are sent back to you. If you look at the header you can see the the sender and the From: are not the same.

More likely it's that, than a spammer spoofing your email.

The call about the computer thing seems like it could be something different but very important to investigate.
Bill is offline   Reply With Quote
Old 2004-03-04, 02:28 AM   #10
Surfn
If you don’t take a chance the Angels won’t dance
 
Surfn's Avatar
 
Join Date: Aug 2003
Location: Earth on occasion
Posts: 8,812
Send a message via ICQ to Surfn
Bill

Yes, it had an attachment, .pif if remember correctly, only a fool would open an unsolicited attachment.
__________________

Surfn's Links Are you a partner?

Surfn is offline   Reply With Quote
Old 2004-03-04, 07:41 AM   #11
Dr Bizzaro
I'm not interested in the facts, I'm interested in my opinion.
 
Dr Bizzaro's Avatar
 
Join Date: Apr 2003
Location: Chicago
Posts: 1,620
Send a message via ICQ to Dr Bizzaro
I got this one from Undergroundlinks.com

Dear user of "Undergroundlinks.com" mailing system,

Your e-mail account will be disabled because of improper using in next three days, if you are still wishing to use it, please, resign your account information.

For further details see the attach.

In order to read the attach you have to use the following password: 17622.

Best wishes,
The Undergroundlinks.com team http://www.undergroundlinks.com
----------------------------------------------------

I was like "wow I can't believe what I could be such a stickler with the rules ."
But then I thought "Well, I can't believe I could be so careless, concerning my email."

So I hid from myself for the rest of the day in my office. I just hope I forget all about it. I wouldn't want to have to take away my email account from me.
Dr Bizzaro is offline   Reply With Quote
Old 2004-03-04, 08:08 AM   #12
Surfn
If you don’t take a chance the Angels won’t dance
 
Surfn's Avatar
 
Join Date: Aug 2003
Location: Earth on occasion
Posts: 8,812
Send a message via ICQ to Surfn
Dr B

Same here
__________________

Surfn's Links Are you a partner?

Surfn is offline   Reply With Quote
Old 2004-03-04, 05:06 PM   #13
RawAlex
Took the hint.
 
Join Date: Mar 2003
Posts: 5,597
Send a message via AIM to RawAlex
Make your life simple: Have your mail program filter and remove ALL attachments and emails with attachments. No attachments means almost no viruses can get to you.

Use hotmail or other for attachment passing... they filter good :-)

Alex
RawAlex is offline   Reply With Quote
Old 2004-03-04, 05:31 PM   #14
Bill
Selling porn allows me to stay in a constant state of Bliss - ain't that a trip!
 
Join Date: Apr 2003
Posts: 3,914
I'll repeat, I suspect these are actual attacks, possibly aimed at adult webmasters, not viruses, because of the small size of the payloads.

You can download attack tools from various "black" sites, these tools are uaually sent as attachments, but they are often smaller than viruses. They are usually things like backdoor installlers or keyboard sniffers or port sniffers.

It's easy to buy mailing lists of adult webmaster emails, and it would be easy for an attacker to use those freely available small size attack tools.

Of course, no-one but an idiot would click on an attachment, some hang-overs notwithstanding...

I don't strip off attachments automatically (for some reason people like sponsors, content providers, and hosting companies still use attachments), but I direct them to an "attachments" folder.
Bill is offline   Reply With Quote
Old 2004-03-04, 07:58 PM   #15
Bill
Selling porn allows me to stay in a constant state of Bliss - ain't that a trip!
 
Join Date: Apr 2003
Posts: 3,914
I may be wrong about it being an attack tool, the more I learn about it the more it seems like it may be a new gimmick, a virus loader instead of a virus itself.

That doesn't mean it still doesn't include attack executables like sniffers, but it seems to load Bagle and other viruses as well, all at once.

There's a new virus war going on. I hope the FBI earns it's pay for once and catches the kiddies.
Bill is offline   Reply With Quote
Reply

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 06:28 PM.


Mark Read
Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
© Greenguy Marketing Inc