New spam angle

Jul 31, 2003 20 Replies

Something just started happening in the spam department that I haven't seen before. I'm getting "undeliverable" messages, apparently legit, telling me that mail I sent to addresses I've never heard of can't be delivered (for legit reasons).



It appears some spammer has decided to use my email address as his bogus return address. Has anyone else seen this happening? I've used recent virus and ad checkers to see if my system is infected with some email sender or whatever, although I don't know enough about those to know if it would be discovered.



Any info will be appreciated.


-- Ed Huntress (remove "3" from email address for email reply)


Are those messages from Mailer Daemon or Mail Administrator or Mailer Subsystems? I got those messages for a while but apparently it was not a virus on my system. Like so many other problems, I just ignored it and it went away.

Fred

I have seen the same thing. I also got one from "e-bay" telling me that the account would be closed if I didn't update the info. In the last month the spam has incresed in volume and deceitfullness. They will try to pick out names and use them for the sender. I have an idea that "real player" had an inbedded program in it because it would be running underneath with not icon on the screen. YOu hit alt-cont- del and can see what is running. Since I deleted realplayer everything seems to run faster and the spam went down by about 5 messages. I never did load realplayer onto the harddrive. I just wonder of you conld send an attachment that would do them in. Who cares about WMD's get rid of spammers.

John

This is the product of viruses. They harvest addresses from people's address book, and use them as the from: address on the virus copies they send out to others in the address book. Some addresses in that address book have been closed, and others have anti-virus scanners on incoming mail, and the messages bounce back to where it appears they came from (you). I have been getting many of these for over a year. At first, I had a fit (how DARE somebody use my name!!!) until I realized this all was coming from virus-infected machines, and was not intentional use by a real person. Sometimes, there's enough info in the message headers that you can actually tell where the original message came from.

I have also gotten the original messages (From: me, To: me) and there you can definitely trace where it really came from, and try to inform them they have a virus.

Jon

That's a variant of the Klez virus.

It 'makes up' To: and From: addresses, as well as using addresses it find in the address book of infected machines.

Cheers, Fred McClellan the dash plumber at mindspring dot com

Desert Traveler wrote:(clip)I didn't need to open the atttachment (clip) ^^^^^^^^^^^^^ Attachment? Could there be a virus in there?

Yeah, all of the above. The ones that supposedly come from my own two ISPs look authentic.

That's probably what I'll do. Thanks, Fred.

Ed Huntress

I was also getting alot of these. I talked to my ISP and he called them "spoofed address". All someone needs to do is put your address in the reply to field of there email program. Sneaky, yes it is, but according to my ISP it is unstoppable. He said it even happens to him sometimes. It is bad enough to get 50 to 100 spam messages a day but then to find the "undeliverables" that I did not send, makes me mad as hell.

Paul in Ohio

Aha. I saw one of those but didn't do anything about it, because I didn't know what was going on.

None of this is unlikely to cause any trouble because I'm catching them all in MailWasher. But it was worrying me. Thanks for the info.

Ed Huntress

Started here yesterday with :

This is an automatically generated Delivery Status Notification.

THIS IS A WARNING MESSAGE ONLY.

YOU DO NOT NEED TO RESEND YOUR MESSAGE.

Delivery to the following recipients has been delayed.

snipped-for-privacy@noyahoo.com

Something about:

"Info about St. Piterburg" Gerry :-)} London, Canada

Sure -- several times. The spammer usually uses one of the addresses from his list of potential victims/recipients, runs off a few spam, then switches to another name and continues. Not too many go out under any single name -- unless you are the victim of a "joe job", a spam run designed to make it look as though you are the spammer to make trouble for you. Most frequent victims of "joe jobs" are the anti-spammers.

If you want to read about what is current in the spamming world, try news.admin.net-abuse.e-mail, which is full of discussions of what the spammers are doing, and with which, and to whom, :-)

You can also learn how to read headers there, and what tools to use, and which headers are untrustworthy. (About the only "Received: " header which can be trusted is the one put there by your mail system, or more often, your ISP's mail system), which will be the topmost one. All the others are almost certainly forged -- often with no attempt to make it even look very real.

That last "Received: " header often includes a forged "HELO" exchange with the other system, containing a fake IP address, and/or a fake system name), and if it is a *good* MTA (Mail Transport Agent), it will put the real IP address (and the real system name, if if can be determined) there for you to compare to the forged information.

If you are lucky, your bounced forged spam will contain enough information so you can prove that it did not really come from your system.

Also -- there is news.admin.net-abuse.sightings, which is filled with reports of spam received by various people.

Note that recent runs of virii are designed to install backdoors to allow spammers to relay through victim systems (and to report infected systems to a specific IRC channel for the convenience of the spammers.) I believe that these virii are now being sent out by the spammers themselves, but I can't prove that.

Good Luck, DoN.

Yes, I have seen the same thing over the last 2 months...and on an email address that I've never given out to anyone.

You are just Now getting those? They have been floating around for at least a year.

Gunner

"Democracy is two wolves and a lamb voting on what to have for lunch. Liberty is a well-armed lamb contesting the vote!" -- Ben Franklin

The above is why you never, ever, not hardly never ever, use Outleak Express. Its vulnerable to such attacks and has been since its inception Ver.01 Hence the nick..Outleak Express.

Get Eudora, Pegasus, any of a host of other non-MicroSloth email clients.

Gunner

"Democracy is two wolves and a lamb voting on what to have for lunch. Liberty is a well-armed lamb contesting the vote!" -- Ben Franklin

Now here is a smart man.

Gunner

"Democracy is two wolves and a lamb voting on what to have for lunch. Liberty is a well-armed lamb contesting the vote!" -- Ben Franklin

Actually, it is easily stoppable, if the powers that be, namely the ISP's, decide to. Word is that they are going to do this deciding probably over the rest of this year, as spamming is getting out of control, and killing the ISPs.

What they need to do is make all ISPs require that a From: address is within their own network, or even that the From: line match one of the known user mailboxes associated with the line the mail came in from. There are some problems with this, as many people answer work mail from home, and vice versa. One way to solve this is for everybody to use the From and Reply to: lines properly. So, if you sent work mail from home, the From: line would have to be your home email account, but the Reply To: line could be anything you want. This would totally prevent people from sending hard to trace email, and also force the source of all mail to really say who it is from, or be blocked by the SENDING party's ISP, who are the only ones who can verify who a sender is!

There are other proposals going around, such as to charge for email. Say 1 cent per message. If you want to spam one million messages, it would cost you $10,000 cash, right away. but, the average user like me would pay ten cents a day. The ISPs could even figure out a grace system, if you ran up a bill of less than $10 a month, they don't have to bill you.

Other proposals are to ban bulk mailings, and anyone who is caught doing it gets their whole ISP blocked for a week. The receiving ISPs, like Verizon, Covad and AOL could just compare messages and immediately find the exact same message sent to some threshold of nnn users, and block all traffic originating from that ISP for a time.

So, I think something is going to be done, by mutual agreement of some number of developed country's ISPs, that will slow this muck to a slow drip. There is no technical problem to do so, just a matter of a bunch of separate entities deciding what is the best course of attack that will be the most resistant to some new and more horrible counterattack.

Jon

Yes. There is some Spam email where this is done. It is probably not a virus.

My ISP has a program on the server called ASK (Active Spam Killer). You need to sign up for it (free) and it has cut my Spam from over 100 per day to essentially zero.

It was a learning experience setting it up as I elected to do all my own editing of a "whitelist". If an email address is in the "whitelist" that email is delivered immediately. Other email is held for seven days during which time the sender receives a polite request to confirm that they sent the mail. If they confirm simply by hitting their reply button then they are added to the whitelist and will not receive that confirm request again.

There is an "ignorelist" and this mail is deleted as it arrives. There is also a "blacklist". This mail is sent back with a not so polite request to stop sending email.

All of these "lists" can be edited by the user. Well after a bit of learning they can be edited but once you understand the program it is quite easy.

You also can go into the email in the seven day holding period. There you can retrieve, delete, or blacklist the sender. Since there is seven days of Spam sitting there it is not something you do on a daily basis.

That is it in a small nutshell. I recommend the program but you would need to urge your ISP to put it on their server.

My blacklist in MailWasher, as of today, contains 4,587 entries. My spam has been tapering off, but there appears to be a small blip upwards now that my employer has posted my email address on our website. Sigh.

Ed Huntress

Well, they DID say they were undeliverable.................... groan.............

Steve

At work we started to get Trojan types mailed from snipped-for-privacy@xxxx.com The xxxx is your company domain. Since our division is several domains melted into one larger domain :-) - we got a number of chances.

Now our scopes at work get them - since they are windows based. Wonderful - Glad Microsoft built and teaches VB to all in worm making. Now I suspect Java - even worse - multi- machine os level. Martin

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required