[Full-Disclosure] Re: Empty emails example

From: Bill Royds (full-disclosure_at_royds.net)
Date: 02/28/04

  • Next message: gabriel rosenkoetter: "[Full-Disclosure] Re: OpenPGP (GnuPG) vs. S/MIME"
    To: <full-disclosure@lists.netsys.com>
    Date: Sat, 28 Feb 2004 15:40:33 -0500
    
    

     
    Received from ISP about empty email I received. If it is not a spammer, it
    could be a virus sending emails without the payload.

    -----Original Message-----
    From: Rory Irvine [mailto:rory@bytel.net.uk]
    Sent: February 28, 2004 3:24 PM
    To: Bill@royds.net
    Subject: Re: spam flood

    Hi,

    > X-SamSpade-Version: 1.14
    >
    > tradeelectronically.com::
    > Your server is being used to flood send emails. Please check into its
    > misuse.
    > ...
    >

    ...

    > > Received: from 80.76.205.232 by 24.147.39.6; Sun, 29 Feb 2004 00:46:57
    > +0500

    ...

    Thanks for bringing this to our attention.

    The IP address in question, 80.76.205.232, belongs to a network that is
    not currently routable. Its appearance in the headers of the spam
    you've received is therefore likely to be a result of a forgery by the
    spammer. Unfortunately, there's not much we can do about this :(

    I notice that you use the words "flood send" - did you receive multiple
    spams appearing to be relayed through that IP? If so, I'd appreciate
    copies of as many of the messages as possible, as it may be eveidence of
    a deliberate attack against our network.

    Rory Irvine
    System Administrator
    Bytel Ltd

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: gabriel rosenkoetter: "[Full-Disclosure] Re: OpenPGP (GnuPG) vs. S/MIME"

    Relevant Pages

    • Re: Identifying spamhosts
      ... >> which machines are the primary routes of spam into our Inboxes. ... your own private rbl ... if you're looking for free lists of "spam ip#" and emails of spammers ...
      (Debian-User)
    • Re: OT my account is being spoofed.
      ... for messages not originating here. ... Is my e-address likely to be blacklisted as a spammer? ... e-mails are simply disguised spam, ... "delivery failure" emails. ...
      (uk.finance)
    • Re: I AM DELIBERATELY SHOUTING!!!
      ... On Dec 8, 9:24 pm, Little Sir Echo ... FLOOD OF SPAM BEING POSTED IN THIS GROUP. ... OR IS THE ONLY AVAILABLE OPTION TO SIMPLY BAIL OUT AND LET THE SPAMMER ...
      (comp.sys.mac.system)
    • Re: mailer-daemon
      ... Some spammer is using your email address as the return address on spam ... emails he sends out. ... Gary VanderMolen, MS-MVP (Mail) ...
      (microsoft.public.windows.vista.mail)
    • I AM DELIBERATELY SHOUTING!!!
      ... SURELY SOMEONE IN THIS GROUP OR ELSEWHERE KNOWS HOW TO PUT A STOP TO THE FLOOD OF SPAM BEING POSTED IN THIS GROUP. ... OR IS THE ONLY AVAILABLE OPTION TO SIMPLY BAIL OUT AND LET THE SPAMMER HAVE THE GROUP ALL TO HIMSELF OR HERSELF? ...
      (comp.sys.mac.system)