-
May 5th, 2003, 12:15 PM
#1
HB Forum Owner
and i don't know how to get rid of it.
i get about 3 a day from the same 'address'...
and, for some reason, i am unable to block
the sender because yahoo doesn't recognize
the email as having a friggin sender...
here's the information:
************************************
X-Apparently-To: [email protected] via 216.136.128.165; 05 May 2003 01:29:37 -0700 (PDT)
Return-Path: [email protected]
Received: from 128.211.219.207 (128.211.219.207) by mta436.mail.yahoo.com with SMTP; 05 May 2003 01:29:33 -0700 (PDT)
Subject: Smallest In World, Digital Camera - So Hot
Reply-to: [email protected]
Date: Mon, 5 May 2003 04:29:23 -0400
From:
Return-Path: [email protected]
To: "Bassage Bethurem" <[email protected]>
X-Originating-Ip: [0.8.847.001]
X-Sender: "Firmin Naguin" <[email protected]>
X-Accept-Language: en
Importance: Normal
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="ILI38J5Q4Gu111TMS00aoAf218lv65OqR7D28061 7I2UTOv6yVkOX"
Content-Transfer-Encoding: 7bit
Content-Length: 1537
*********************************
now tell me how to get rid of this obnoxious bastard
-
May 5th, 2003, 12:43 PM
#2
HB Forum Owner
Maybe you should order one of his cameras!!!
-
May 5th, 2003, 01:21 PM
#3
Cyalaytr
Guest
Ever attend or send your email to anyone at Purdue?? This is where it looks like it it coming from unless he is using a mail forwarding server. Contect the tech guy they or forward the spam back to them.
CYA
OrgName: Purdue University
OrgID: PURDUE
Address: Computer Science Department
City: West Lafayette
StateProv: IN
PostalCode: 47907-2004
Country: US
NetRange: 128.211.0.0 - 128.211.255.255
CIDR: 128.211.0.0/16
NetName: PURDUE-CS-CYP
NetHandle: NET-128-211-0-0-1
Parent: NET-128-0-0-0-0
NetType: Direct Assignment
NameServer: PENDRAGON.CS.PURDUE.EDU
NameServer: MOE.RICE.EDU
NameServer: NS.PURDUE.EDU
NameServer: HARBOR.ECN.PURDUE.EDU
Comment: All SPAM and Abuse complaints should be sent to [email protected]
RegDate:
Updated: 2003-01-15
AbuseHandle: PUISP-ARIN
AbuseName: Purdue University IT Security and Policy
AbusePhone: +1-765-496-8289
AbuseEmail: [email protected]
TechHandle: DT50-ARIN
TechName: Trinkle, Daniel
TechPhone: +1-765-494-7844
TechEmail: [email protected]
-
May 5th, 2003, 01:37 PM
#4
Inactive Member
-
May 5th, 2003, 01:44 PM
#5
HB Forum Owner
i emailed the bastard at the purdue addy provided.
we shall see if anything comes of this barrage.
i hope this damn spam doesn't pay for some
jackass's college....
the results of this email i've sent will also
show how efficient and trustworthy the IP tracers
are (both yours and mine, cya).
stay tuned
-
May 5th, 2003, 02:25 PM
#6
Cyalaytr
Guest
What is interesting though unless they have some mail abuse policy for employee's there and campus students... don't expect too much. For as far as I know most email programs are set upt o block incoming mail from certain IP's or block of IP ranges or even maybe they could block your domain if users on their end were hitting a site they weren't spose to get to. But I don't know of any way they can resrict mail to just one individual going out from their server. Hopefully their program in repremanding the user on their end is quicker and faster then I can imagine.
If your email to the spam dept didnt work... email root at the server and it will go to network specialist or server manager. You get his attention win him on your side and he will just close his dang IP just so he doesn't have to get his butt chewed or put up with the crap.
CYA
-
May 5th, 2003, 02:39 PM
#7
HB Forum Owner
i don't think the person selling the cams
actually works at purdue... in fact, i think
its some punk kid using his/her student account
in order to send out spam. naturally this
IP addy is deflected and purdue is brought up.
what i'm curious about is the other various
email addies displayed in the information...
what are those??
hmmmmmmmmm.... *scratches chin and raises an eyebrow*
-
May 5th, 2003, 02:55 PM
#8
Cyalaytr
Guest
The first thing to do is to display the full headers of the spam message. The recipient of a complaint is going to need those to be able to determine (a) that the spam did in fact come from his/her ISP, and (b) who was responsible for it. In Outlook Express, click on "File" then "Message Properties". In the dialog box that opens, click "Details". This can be copied and transferred to a text editor, or to another message to be forwarded to an ISP abuse controller.
<font color="red">Return-Path: [email protected] </font>
Received: from mta7-rme.xtra.co.nz (pop6-rme.xtra.co.nz [203.96.92.23]) by mx2.clear.net.nz (1.5/1.28) with ESMTP id MAA20690; Sun, 5 Aug 2001 12:07:20 +1200 (NZST)
Received: from quantick ([210.86.32.75]) by mta7-rme.xtra.co.nz with SMTP id
<20010805001246.NTBH88267.mta7-rme.xtra.co.nz@quantick>
for <[email protected]>; Sun, 5 Aug 2001 12:12:46 +1200
Message-ID: <003101c11d43$4cdab320$0100007f@quantick>
<font color="red">From: "Steven Quantick" <[email protected]>
To: "Philip Ross" <[email protected]>
Subject: Hi from Wairoa.
Date: Sun, 5 Aug 2001 12:03:01 +1200 </font>
MIME-Version: 1.0
Content-Type: multipart/related;
type="multipart/alternative";
boundary="----=_NextPart_000_02DF_01C15F30.7B393460"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.50.4522.1200
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4133.2400
X-Envelope-To: [email protected]
X-UIDL: 5abdc37a107abad8bdfd4981f3210db3
The first thing to be noted is that there are a number of lines that commence with "Received:". Each computer through which the mail passes adds one of these of lines. These can be forged, but usually forgeries are fairly obvious. The easiest elements to forge are those whose text has been rendered in red above. All of these are user-inputs which can be forged by anyone from any mailer. The received lines comprise a number of elements as demonstrated by the first one, which has been parsed into its constituents by means of different colour use above. The blue text is the name of the mail agent at my ISP that received the message. Inside square brackets alongside it, in green, is a set of numbers. These are the results of a reverse DNS lookup performed by my ISP. In other words, my ISP queried the sender as to its identity (a good thing). In brown, next to that, is the name that my ISP identified as belonging to the IP address it found when it performed the reverse lookup. Finally, in navy blue, is the name by which the originating computer identified itself. This matches substantially to the name my ISP matched to the IP address -- which indicates that the sending computer told the truth as to its origins. If the names do not match, it may indicate forgery, but using the Whois lookup (refer to the page trace.html for more information on this) check out the identity of the organisation to whom the IP address is registered. Sadly, not every organisation performs a reverse DNS lookup.
There are usually several such sets of lines. These should form a continuous, unbroken path to your computer, and as you work downwards, you move backwards towards the origin of the email. In the example above, it will be seen that a computer calling itself "quantick" transmitted the email to the mail transport agent at Xtra. Since the email was sent by someone named "Quantick" this is hardly surprising. The reverse DNS lookup has generated another IP address, which if checked, will turn out to be a dial up connection to the ISP, Xtra.
There are a number of other observations that could be made about these headers. It will be noted that the date and time that the message was sent ae included. These should conform to the originator's physical location and should match the time zone in which he/she resides. In this case, the email was sent during NZ Standard Time and this is, as the message says, +12 hours from UTC. Often, a spam will have plainly impossible time zone information here; for instance, something purporting that US Eastern Standard Time is -7 hours, when in fact it is -5 hours. Such mis-matches are solid evidence of forgery or tampering with the headers.
Below is an example of a spam message that contains forged information (highlighted in red):
Return-Path: <[email protected]>
Received: from imation.imation.co.kr ([211.37.11.170]) by mx1.clear.net.nz (1.5/1.31) with ESMTP id QAA22541; Tue, 1 Jan 2002 16:59:11 +1300 (NZDT)
<font color="red">Received: from smtp.hanimail.com </font>(203.46.91.40 [203.46.91.40]) by imation.imation.co.kr with SMTP (Microsoft Exchange Internet Mail Service Version 5.5.1960.3)
id ZYA6AVXH; Tue, 1 Jan 2002 13:11:08 +0900
<font color="red">Message-ID: <[email protected] m> </font>
To: <Undisclosed.Recipients>
<font color="red">From: "Britney" <[email protected]>
Subject: Re: CSWGJ
Date: Tue, 01 Jan 2002 13:56:23 -0200 </font>
MIME-Version: 1.0
Content-Type: text/plain; charset="Windows-1252"
Content-Transfer-Encoding: 7bit
X-Envelope-To: [email protected]
X-UIDL: bcd062fc4f0fcf5a49f1109ce77a0453
How do I know that the purported address and origin are forgeries? The return path and origin have been forged to appear as through they are an organisation called "hanimail.com" but this does not match the reverse DNS performed by one of the intermediate hosts (blue). This IP number actually belongs to Telstra, Australia and that is the ISP to whom a complaint should be made in this instance (and indeed this was done).
But wait... it's not quite that easy...
Unfortunately, it is common for a spammer to bounce mail through a third party, who has an operative open relay. In that case, the mail headers will not identify the originating ISP at all, but merely the unfortunate third party whose servers were misused. It is worth advising the point of origin of the problem with their open relay as with any luck they will close it and there will be fewer such holes for spammers to exploit in the future. It is usually quite obvious when a spammer has used an open relay. In one case, when I received an email which came through an open relay, I tested it by creating a fictitious identity and relaying a message back to myself (headers below). After proving it was an open relay, I sent a message to the server administrator advising him of the problem.
Received: from mail.sankyo-sports.co.jp ([211.0.27.34]) by mail.inhb.co.nz (Merak 4.10.040) with ESMTP id GPA37165 for <[email protected]>; Wed, 28 Nov 2001 09:12:48 +1300
Received: from desktop (localhost [127.0.0.1]) by mail.sankyo-sports.co.jp (8.9.3+3.2W/3.7W) with SMTP id FAA04750 for <[email protected]>; Wed, 28 Nov 2001 05:09:19 +0900
Message-ID: <001601c1777e$c16e4ae0$e77cfea9@desktop>
Reply-To: "sarge57" <[email protected]>
From: "sarge57" <[email protected]>
To: <[email protected]>
Subject: Test
Date: Wed, 28 Nov 2001 09:02:42 +1300
Organization: spammers are liars
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="----=_NextPart_000_0011_01C177EB.6FDC1A00"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.50.4133.2400
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4133.2400
In fact, though this message looks like it originates from sankyo-sports.co.jp, it didn't -- I sent it from clear.net.nz. The name "localhost" and the reverse DNS are correct, for my machine -- but localhost always resides at 127.0.0.1 and the information does not assist one in establishing the ISP from which the message originated. However, it is appropriate to complain to the host of the open relay as when they close it, there is one less such hole in the internet available for spam mailers. The fake reply to and from addresses were taken from a spam mailing that had come through this loophole.
The good news is that the headers can always be traced, at least to a certain extent, and complaints made. If in doubt, complain to [email protected]in. Responsible ISPs take vigorous and swift action to remove spammers from their systems, and some ISPs are now taking legal action against spammers who fake their identities.
courtisy of Safeguard.co.nz
CYA
Hope this helps ya [img]eek.gif[/img]
-
May 6th, 2003, 03:10 AM
#9
HB Forum Owner
aye.
when i grabbed the info (that i posted here)...
i noticed that some obvious external coding
tricks that kept certain information hidden...
we shall see what the email does
-
May 6th, 2003, 03:25 AM
#10
Cyalaytr
Guest
It is all a game people play of who is better at the keyboard clicking. Don't let him. If he is just sending spam out he prolly doesn have a brain cell left enough to have a Commador 64. Anyhow he could have been using an Anonymous reMailer. Just play his game and send him spam back. Anonymous Remailer site
He wont be able to tell who it is from and if you find a big enough file for what ever server he or she is using it will do 2 things
1) if he is using a work email. The network specialist will see the jump in his email usage and start watching it
2) if he is using yahoo or hotmail you will fill his account and until he empties it the account is un-usable for him reciving new mail. :-)
Ahhh what a world we live in.
CYA
Or you can really scare him and trace his IP take a satelite pic of his house and mail it to him asking him to stop. But that may be a bit much. *giggle*
<font color="#c0c0c0" size="1">[ May 05, 2003 12:28 PM: Message edited by: Cyalaytr ]</font>
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
Bookmarks