Re: Blank Emails



On Thu, 09 Feb 2006, in the Usenet newsgroup alt.computer.security, in article
<5VyGf.136914$PY6.119844@xxxxxxxxxxxxxxxxxxxxxx>, John Gregory wrote:

Over the past week or two, I've begun receiving blank emails from unknown
sources for no apparent reason.

Phonebook or dictionary attack on the mail server. Spammers are using
zombies to try sending mail to common names or name sequences (such as
a last name with leading or trailing initial ['jdoe' or 'doej'] or trailing
number [doe23]) to get current lists of valid usernames. If the mail
server accepts the mail, the username is valid, and is added to the list
of valued contacts who want to receive spam. If the username is rejected,
the name doesn't get added. The list may then be sold to other spammers.

I did note that a number seemed to be originating from an edu extension
in New York state.

In theory, you could complain to your ISP. Probably won't do much good.

I never open then but I can tell they're blank from the preview window my
Outlook 2003 Inbox.

Get a real mail tool.

Here's the latest Xqogfkq@xxxxxxxxxxxxx I guess this is webmail.

More likely it's just the output of a random character generator and is
totally meaningless. The "From:" header is part of the contents of the mail,
which is actually delivered based on what is called the 'envelope sender'.
You only see that information when looking in the 'Received: header put on
the mail by your ISP's mail server.

Any idea what's going on here?

Normal spammer activity.

Old guy
.



Relevant Pages

  • Re: [Full-Disclosure] Im calling for LycosEU heads and team to resign or be sacked
    ... To go back to a previous message; in attacking spammers, ... I run a small mail server that services about 10 domains. ... I have approximately 500MB of spam stored on my server. ... bandwidth fees to upload disk images to a remote server. ...
    (Full-Disclosure)
  • Re: [Full-Disclosure] Im calling for LycosEU heads and team to resign or be sacked
    ... I woud recommend a nice email detailing the real damage and spiritual damage caused by spam, aned what they might do to find a better way to make a living.. ... Lots of spammers are simply trying to make a living, and don't feel they have other options. ... How will we pay for damages, ... I run a small mail server that services about 10 domains. ...
    (Full-Disclosure)
  • RE: Delivery Status Notification (Failure)
    ... I do not think that I am under threat from spammers. ... Delivery status notifications in Exchange Server and in Small Business ... Spammer telnet a third party Mail Server by port 25, ... Microsoft SMTP Servers May Seem to Accept and Relay E-Mail ...
    (microsoft.public.windows.server.sbs)
  • AW: [ISN] Majordomo Could Mean Major Spam
    ... I seriously doubt that spammers will really process the robots.txt. ... If you look at the web archives of securityfocus lists you will see that the ... Betreff: Re: Majordomo Could Mean Major Spam ...
    (Security-Basics)
  • Re: Optimal wildcard search algorithm
    ... Then, for the second round, aa*, ab* ... after the two rounds of bruteforcing, ... error for a wildcarded username that does exist but can't be bound to, ... > or similar, some username/password combo lists, etc. ...
    (Pen-Test)