Web Hosting Forum | Lunarpages


*
Welcome, Guest. Please login or register.
Did you miss your activation email?



Login with username, password and session length
May 24, 2012, 09:08:00 AM

Pages: [1]   Go Down
  Print  
Author Topic: Help! My email address has been hijacked!  (Read 744 times)
David SF
Space Explorer
***
Offline Offline

Posts: 6


« on: July 31, 2003, 06:37:55 PM »

I'm not sure where to post this, but I do need some advice. Based on the number of "Mail Delivery Subsystem, Returned mail: User unknown" I have started to get, it's become obvious that some spammer is using my email address from my domain here as his spammer return address. The first sign was a couple weeks ago when I got a "refused delivery" form back from an ISP saying that I was a "known spammer". That confused me, but the Returned Mail I am getting confirms my suspicions.

Is there anything I can do about this? I have looked through the mail headers, and the replies are all coming from AOL via lunarpages to my forwarding address, and there doesn't seem to be a way to figure out who the real sender is.

Thanks for any advice!
Logged
TWebMan
Quantum Encyclopedia Writer
*****
Offline Offline

Posts: 3112



WWW
« Reply #1 on: July 31, 2003, 06:42:12 PM »

Is there an originating IP?  It's difficult to spoof a header without having some kind of control over a server.  Paste a full header here and let's have a look.

  In the meantime, is this a critical account?  Can you blackhole it for now?  Set a filter to discard?
Logged

"Computers cause people to make more mistakes than any other invention in history, with the possible exception of handguns and tequila."  - Unknown
"Liberty of any kind is seldom lost all at once." - D. Hume
Every day is an Ode to Joy
The planet will be fine... and so will your site
David SF
Space Explorer
***
Offline Offline

Posts: 6


« Reply #2 on: July 31, 2003, 06:46:48 PM »

Yes, unfortunately it is critical. It is the only way 99% of the world can reach me, since I set up my domain just to avoid ever changing email addresses if my underlying ISP changed.

Here's a header I got today. I don't fully understand each line:

X-Apparently-To: dgf@sbcglobal.net [my forward] via web80411.mail.yahoo.com; 31 Jul 2003 17:07:34 -0700 (PDT)
X-YahooFilteredBulk: 64.235.234.121
Return-Path: <>
Received: from vmc-ext.prodigy.net (207.115.63.88)
  by mta813.mail.yahoo.com with SMTP; 31 Jul 2003 17:07:34 -0700 (PDT)
X-Originating-IP: [64.235.234.121]
Received: from taurus.lunarpages.com (taurus.lunarpages.com [64.235.234.121])
   by vmc-ext.prodigy.net (8.12.9/8.12.3) with ESMTP id h7106Y6t666612
   for <dgf@sbcglobal.net>; Thu, 31 Jul 2003 20:06:52 -0400
Received: from [205.188.159.1] (helo=omr-d03.mx.aol.com)
   by taurus.lunarpages.com with esmtp (Exim 4.20)
   id 19iNRx-0003DK-5u
   for david@fridley.net [my domain address]; Thu, 31 Jul 2003 17:07:13 -0700
Received: from  str-m01.mail.aol.com (str-m01.mail.aol.com [172.21.28.97]) by omr-d03.mx.aol.com (v90_r2.6) with ESMTP id RELAYIN1-0731200556; Thu, 31 Jul 2003 20:05:56 2000
Received: from localhost (localhost)
     by str-m01.mail.aol.com (8.8.8/8.8.8/AOL-5.0.0)
     with internal id UAA12242;
     Thu, 31 Jul 2003 20:05:55 -0400 (EDT)
Date: Thu, 31 Jul 2003 20:05:55 -0400 (EDT)
From: Mail Delivery Subsystem <MAILER-DAEMON@aol.com>
Message-Id: <200308010005.UAA12242@str-m01.mail.aol.com>
To: <david@fridley.net>
MIME-Version: 1.0
Content-Type: multipart/report; report-type=delivery-status;
   boundary="UAA12242.1059696355/str-m01.mail.aol.com"
Subject: Returned mail: User unknown
Auto-Submitted: auto-generated (failure)
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - taurus.lunarpages.com
X-AntiAbuse: Original Domain - fridley.net
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain -
Logged
David SF
Space Explorer
***
Offline Offline

Posts: 6


« Reply #3 on: July 31, 2003, 06:51:19 PM »

Oh, and these were included as attachments:

Received: from  rly-xe04.mx.aol.com (rly-xe04.mail.aol.com [172.20.105.196]) by str-m01.mail.aol.com (v92.16) with ESMTP id RELAYIN10-b3f29add55a; Thu, 31 Jul 2003 20:01:25 -0400
Received: from  fridley.net ([61.171.252.175]) by rly-xe04.mx.aol.com (v95.1) with ESMTP id MAILRELAYINXE48-42c3f29adc4109; Thu, 31 Jul 2003 20:01:13 -0400
Message-ID: <04c501c357b0$6f4ca360$0a8fa263@bga>
Reply-To: david@fridley.net
From: david@fridley.net
To: "hcchan" <wbckabo0m@aol.com>
Cc: <wbckbizkit@aol.com>
Subject: xkigbwaoe bbxoayq I got this from my co-worker. It is a good one to keep on hand.
Date: Fri, 01 Aug 2003 01:09:38 +0300
MIME-Version: 1.0
Content-Type: multipart/alternative;
   boundary="----=_NextPart_817_4775_E399F7F8.1AD7FC1A"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.00.2919.6700
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2919.6700
X-AOL-IP: 61.171.252.175
X-AOL-SCOLL-SCORE: 0:XXX:XX
X-AOL-SCOLL-URL_COUNT: 0

and

Reporting-MTA: dns; str-m01.mail.aol.com
Arrival-Date: Thu, 31 Jul 2003 20:01:26 -0400 (EDT)

Final-Recipient: RFC822; wbckabo0m@aol.com
Action: failed
Status: 5.1.1
Remote-MTA: DNS; airmail-04.mail.aol.com
Diagnostic-Code: SMTP; 550 MAILBOX NOT FOUND
Last-Attempt-Date: Thu, 31 Jul 2003 20:05:55 -0400 (EDT)
Logged
TWebMan
Quantum Encyclopedia Writer
*****
Offline Offline

Posts: 3112



WWW
« Reply #4 on: August 01, 2003, 04:55:41 AM »

Are you running a FormMail script, or any other type of mail script where the recipients are in a hidden form field, or any mail script where the user can set the recipient(s)?
Logged

"Computers cause people to make more mistakes than any other invention in history, with the possible exception of handguns and tequila."  - Unknown
"Liberty of any kind is seldom lost all at once." - D. Hume
Every day is an Ode to Joy
The planet will be fine... and so will your site
David SF
Space Explorer
***
Offline Offline

Posts: 6


« Reply #5 on: August 01, 2003, 06:22:08 AM »

No, I have never used these kind of functions, have never enabled mail from my website, and even switched all mailtos to graphics because of spam-bots. The irony.
Logged
jinyao
Newbie
*
Offline Offline

Posts: 5


« Reply #6 on: August 03, 2003, 08:42:08 PM »

Unfortunately, I'm afraid there's little you can do except legal means.  SMTP protocol allows a email message use any address in the FROM field, even it is invalid. My yahoo address was once used by spammers. One possiblity is the spammer  got my email address from the Internic domain registration database -- the one publishes each domain name and its administrative/tech contact.
Logged
pheared
Galactic Royalty
*****
Offline Offline

Posts: 203



WWW
« Reply #7 on: August 05, 2003, 05:22:25 PM »

David, I'm being subjected to this as well.  Most of the bounced messages contain the original spam and you can see my address set in the From header and in the Return-Path header.  They are abusing open proxies, not sending through lunarpages.

This is pretty lame.
Logged

Pages: [1]   Go Up
  Print  
 
Jump to: