Page 1 of 2 12 LastLast
Results 1 to 10 of 14

Thread: i keep receiving this spam

  1. #1
    HB Forum Owner SHATOUSHKA's Avatar
    Join Date
    March 18th, 2001
    Posts
    22,191
    Follows
    0
    Following
    0
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Quoted
    0 Post(s)

    Post

    and i don't know how to get rid of it.
    i get about 3 a day from the same 'address'...
    and, for some reason, i am unable to block
    the sender because yahoo doesn't recognize
    the email as having a friggin sender...

    here's the information:

    ************************************

    X-Apparently-To: [email protected] via 216.136.128.165; 05 May 2003 01:29:37 -0700 (PDT)
    Return-Path: [email protected]
    Received: from 128.211.219.207 (128.211.219.207) by mta436.mail.yahoo.com with SMTP; 05 May 2003 01:29:33 -0700 (PDT)
    Subject: Smallest In World, Digital Camera - So Hot
    Reply-to: [email protected]
    Date: Mon, 5 May 2003 04:29:23 -0400
    From:
    Return-Path: [email protected]
    To: "Bassage Bethurem" <[email protected]>
    X-Originating-Ip: [0.8.847.001]
    X-Sender: "Firmin Naguin" <[email protected]>
    X-Accept-Language: en
    Importance: Normal
    MIME-Version: 1.0
    Content-Type: multipart/alternative; boundary="ILI38J5Q4Gu111TMS00aoAf218lv65OqR7D28061 7I2UTOv6yVkOX"
    Content-Transfer-Encoding: 7bit
    Content-Length: 1537

    *********************************

    now tell me how to get rid of this obnoxious bastard

  2. #2
    HB Forum Owner KingBean's Avatar
    Join Date
    August 17th, 2002
    Location
    Where Boys Fear To Tread.
    Posts
    11,022
    Follows
    0
    Following
    0
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Quoted
    0 Post(s)

    Post

    Maybe you should order one of his cameras!!!

  3. #3
    Cyalaytr
    Guest Cyalaytr's Avatar

    Post

    Ever attend or send your email to anyone at Purdue?? This is where it looks like it it coming from unless he is using a mail forwarding server. Contect the tech guy they or forward the spam back to them.

    CYA

    OrgName: Purdue University
    OrgID: PURDUE
    Address: Computer Science Department
    City: West Lafayette
    StateProv: IN
    PostalCode: 47907-2004
    Country: US

    NetRange: 128.211.0.0 - 128.211.255.255
    CIDR: 128.211.0.0/16
    NetName: PURDUE-CS-CYP
    NetHandle: NET-128-211-0-0-1
    Parent: NET-128-0-0-0-0
    NetType: Direct Assignment
    NameServer: PENDRAGON.CS.PURDUE.EDU
    NameServer: MOE.RICE.EDU
    NameServer: NS.PURDUE.EDU
    NameServer: HARBOR.ECN.PURDUE.EDU
    Comment: All SPAM and Abuse complaints should be sent to [email protected]
    RegDate:
    Updated: 2003-01-15

    AbuseHandle: PUISP-ARIN
    AbuseName: Purdue University IT Security and Policy
    AbusePhone: +1-765-496-8289
    AbuseEmail: [email protected]

    TechHandle: DT50-ARIN
    TechName: Trinkle, Daniel
    TechPhone: +1-765-494-7844
    TechEmail: [email protected]

  4. #4
    Inactive Member zelazny's Avatar
    Join Date
    July 8th, 2001
    Posts
    3,495
    Follows
    0
    Following
    0
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Quoted
    0 Post(s)

    *worships cyalaytr*

  5. #5
    HB Forum Owner SHATOUSHKA's Avatar
    Join Date
    March 18th, 2001
    Posts
    22,191
    Follows
    0
    Following
    0
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Quoted
    0 Post(s)

    Post

    i emailed the bastard at the purdue addy provided.

    we shall see if anything comes of this barrage.
    i hope this damn spam doesn't pay for some
    jackass's college....

    the results of this email i've sent will also
    show how efficient and trustworthy the IP tracers
    are (both yours and mine, cya).

    stay tuned

  6. #6
    Cyalaytr
    Guest Cyalaytr's Avatar

    Post

    What is interesting though unless they have some mail abuse policy for employee's there and campus students... don't expect too much. For as far as I know most email programs are set upt o block incoming mail from certain IP's or block of IP ranges or even maybe they could block your domain if users on their end were hitting a site they weren't spose to get to. But I don't know of any way they can resrict mail to just one individual going out from their server. Hopefully their program in repremanding the user on their end is quicker and faster then I can imagine.

    If your email to the spam dept didnt work... email root at the server and it will go to network specialist or server manager. You get his attention win him on your side and he will just close his dang IP just so he doesn't have to get his butt chewed or put up with the crap.

    CYA

  7. #7
    HB Forum Owner SHATOUSHKA's Avatar
    Join Date
    March 18th, 2001
    Posts
    22,191
    Follows
    0
    Following
    0
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Quoted
    0 Post(s)

    Post

    i don't think the person selling the cams
    actually works at purdue... in fact, i think
    its some punk kid using his/her student account
    in order to send out spam. naturally this
    IP addy is deflected and purdue is brought up.

    what i'm curious about is the other various
    email addies displayed in the information...
    what are those??

    hmmmmmmmmm.... *scratches chin and raises an eyebrow*

  8. #8
    Cyalaytr
    Guest Cyalaytr's Avatar

    Post

    The first thing to do is to display the full headers of the spam message. The recipient of a complaint is going to need those to be able to determine (a) that the spam did in fact come from his/her ISP, and (b) who was responsible for it. In Outlook Express, click on "File" then "Message Properties". In the dialog box that opens, click "Details". This can be copied and transferred to a text editor, or to another message to be forwarded to an ISP abuse controller.

    <font color="red">Return-Path: [email protected] </font>
    Received: from mta7-rme.xtra.co.nz (pop6-rme.xtra.co.nz [203.96.92.23]) by mx2.clear.net.nz (1.5/1.28) with ESMTP id MAA20690; Sun, 5 Aug 2001 12:07:20 +1200 (NZST)
    Received: from quantick ([210.86.32.75]) by mta7-rme.xtra.co.nz with SMTP id
    <20010805001246.NTBH88267.mta7-rme.xtra.co.nz@quantick>
    for <[email protected]>; Sun, 5 Aug 2001 12:12:46 +1200
    Message-ID: <003101c11d43$4cdab320$0100007f@quantick>
    <font color="red">From: "Steven Quantick" <[email protected]>
    To: "Philip Ross" <[email protected]>
    Subject: Hi from Wairoa.
    Date: Sun, 5 Aug 2001 12:03:01 +1200 </font>
    MIME-Version: 1.0
    Content-Type: multipart/related;
    type="multipart/alternative";
    boundary="----=_NextPart_000_02DF_01C15F30.7B393460"
    X-Priority: 3
    X-MSMail-Priority: Normal
    X-Mailer: Microsoft Outlook Express 5.50.4522.1200
    X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4133.2400
    X-Envelope-To: [email protected]
    X-UIDL: 5abdc37a107abad8bdfd4981f3210db3


    The first thing to be noted is that there are a number of lines that commence with "Received:". Each computer through which the mail passes adds one of these of lines. These can be forged, but usually forgeries are fairly obvious. The easiest elements to forge are those whose text has been rendered in red above. All of these are user-inputs which can be forged by anyone from any mailer. The received lines comprise a number of elements as demonstrated by the first one, which has been parsed into its constituents by means of different colour use above. The blue text is the name of the mail agent at my ISP that received the message. Inside square brackets alongside it, in green, is a set of numbers. These are the results of a reverse DNS lookup performed by my ISP. In other words, my ISP queried the sender as to its identity (a good thing). In brown, next to that, is the name that my ISP identified as belonging to the IP address it found when it performed the reverse lookup. Finally, in navy blue, is the name by which the originating computer identified itself. This matches substantially to the name my ISP matched to the IP address -- which indicates that the sending computer told the truth as to its origins. If the names do not match, it may indicate forgery, but using the Whois lookup (refer to the page trace.html for more information on this) check out the identity of the organisation to whom the IP address is registered. Sadly, not every organisation performs a reverse DNS lookup.

    There are usually several such sets of lines. These should form a continuous, unbroken path to your computer, and as you work downwards, you move backwards towards the origin of the email. In the example above, it will be seen that a computer calling itself "quantick" transmitted the email to the mail transport agent at Xtra. Since the email was sent by someone named "Quantick" this is hardly surprising. The reverse DNS lookup has generated another IP address, which if checked, will turn out to be a dial up connection to the ISP, Xtra.

    There are a number of other observations that could be made about these headers. It will be noted that the date and time that the message was sent ae included. These should conform to the originator's physical location and should match the time zone in which he/she resides. In this case, the email was sent during NZ Standard Time and this is, as the message says, +12 hours from UTC. Often, a spam will have plainly impossible time zone information here; for instance, something purporting that US Eastern Standard Time is -7 hours, when in fact it is -5 hours. Such mis-matches are solid evidence of forgery or tampering with the headers.

    Below is an example of a spam message that contains forged information (highlighted in red):

    Return-Path: <[email protected]>
    Received: from imation.imation.co.kr ([211.37.11.170]) by mx1.clear.net.nz (1.5/1.31) with ESMTP id QAA22541; Tue, 1 Jan 2002 16:59:11 +1300 (NZDT)
    <font color="red">Received: from smtp.hanimail.com </font>(203.46.91.40 [203.46.91.40]) by imation.imation.co.kr with SMTP (Microsoft Exchange Internet Mail Service Version 5.5.1960.3)
    id ZYA6AVXH; Tue, 1 Jan 2002 13:11:08 +0900
    <font color="red">Message-ID: <[email protected] m> </font>
    To: <Undisclosed.Recipients>
    <font color="red">From: "Britney" <[email protected]>
    Subject: Re: CSWGJ
    Date: Tue, 01 Jan 2002 13:56:23 -0200 </font>
    MIME-Version: 1.0
    Content-Type: text/plain; charset="Windows-1252"
    Content-Transfer-Encoding: 7bit
    X-Envelope-To: [email protected]
    X-UIDL: bcd062fc4f0fcf5a49f1109ce77a0453


    How do I know that the purported address and origin are forgeries? The return path and origin have been forged to appear as through they are an organisation called "hanimail.com" but this does not match the reverse DNS performed by one of the intermediate hosts (blue). This IP number actually belongs to Telstra, Australia and that is the ISP to whom a complaint should be made in this instance (and indeed this was done).

    But wait... it's not quite that easy...

    Unfortunately, it is common for a spammer to bounce mail through a third party, who has an operative open relay. In that case, the mail headers will not identify the originating ISP at all, but merely the unfortunate third party whose servers were misused. It is worth advising the point of origin of the problem with their open relay as with any luck they will close it and there will be fewer such holes for spammers to exploit in the future. It is usually quite obvious when a spammer has used an open relay. In one case, when I received an email which came through an open relay, I tested it by creating a fictitious identity and relaying a message back to myself (headers below). After proving it was an open relay, I sent a message to the server administrator advising him of the problem.

    Received: from mail.sankyo-sports.co.jp ([211.0.27.34]) by mail.inhb.co.nz (Merak 4.10.040) with ESMTP id GPA37165 for <[email protected]>; Wed, 28 Nov 2001 09:12:48 +1300
    Received: from desktop (localhost [127.0.0.1]) by mail.sankyo-sports.co.jp (8.9.3+3.2W/3.7W) with SMTP id FAA04750 for <[email protected]>; Wed, 28 Nov 2001 05:09:19 +0900
    Message-ID: <001601c1777e$c16e4ae0$e77cfea9@desktop>
    Reply-To: "sarge57" <[email protected]>
    From: "sarge57" <[email protected]>
    To: <[email protected]>
    Subject: Test
    Date: Wed, 28 Nov 2001 09:02:42 +1300
    Organization: spammers are liars
    MIME-Version: 1.0
    Content-Type: multipart/alternative; boundary="----=_NextPart_000_0011_01C177EB.6FDC1A00"
    X-Priority: 3
    X-MSMail-Priority: Normal
    X-Mailer: Microsoft Outlook Express 5.50.4133.2400
    X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4133.2400


    In fact, though this message looks like it originates from sankyo-sports.co.jp, it didn't -- I sent it from clear.net.nz. The name "localhost" and the reverse DNS are correct, for my machine -- but localhost always resides at 127.0.0.1 and the information does not assist one in establishing the ISP from which the message originated. However, it is appropriate to complain to the host of the open relay as when they close it, there is one less such hole in the internet available for spam mailers. The fake reply to and from addresses were taken from a spam mailing that had come through this loophole.

    The good news is that the headers can always be traced, at least to a certain extent, and complaints made. If in doubt, complain to [email protected]in. Responsible ISPs take vigorous and swift action to remove spammers from their systems, and some ISPs are now taking legal action against spammers who fake their identities.


    courtisy of Safeguard.co.nz

    CYA

    Hope this helps ya [img]eek.gif[/img]

  9. #9
    HB Forum Owner SHATOUSHKA's Avatar
    Join Date
    March 18th, 2001
    Posts
    22,191
    Follows
    0
    Following
    0
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Quoted
    0 Post(s)

    Post

    aye.

    when i grabbed the info (that i posted here)...
    i noticed that some obvious external coding
    tricks that kept certain information hidden...

    we shall see what the email does

  10. #10
    Cyalaytr
    Guest Cyalaytr's Avatar

    Post

    It is all a game people play of who is better at the keyboard clicking. Don't let him. If he is just sending spam out he prolly doesn have a brain cell left enough to have a Commador 64. Anyhow he could have been using an Anonymous reMailer. Just play his game and send him spam back. Anonymous Remailer site

    He wont be able to tell who it is from and if you find a big enough file for what ever server he or she is using it will do 2 things

    1) if he is using a work email. The network specialist will see the jump in his email usage and start watching it

    2) if he is using yahoo or hotmail you will fill his account and until he empties it the account is un-usable for him reciving new mail. :-)

    Ahhh what a world we live in.

    CYA

    Or you can really scare him and trace his IP take a satelite pic of his house and mail it to him asking him to stop. But that may be a bit much. *giggle*

    <font color="#c0c0c0" size="1">[ May 05, 2003 12:28 PM: Message edited by: Cyalaytr ]</font>

Page 1 of 2 12 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •