Go Back   Velocity Reviews > Newsgroups > Computer Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply

Computer Security - An odd case of email identity theft?

 
Thread Tools Search this Thread
Old 08-19-2003, 10:34 PM   #1
Default An odd case of email identity theft?


I maintain several different email accounts, although all through the same
provider. Earlier today I got a "returned mail" message on one of my
lesser-used accounts. It said that my email to some address I didn't know
had permanent fatal errors blah blah blah... The weird part was that when I
checked out the supposed original message, it was all in RUSSIAN... and in
performing a whois trace, I saw that the domain of the target address was
also RUSSIAN. Can anyone explain how this happens? Do I have to be
concerned that someone has picked off access to one or all of my email
accounts?

Thx.




Wha?
  Reply With Quote
Old 08-19-2003, 11:33 PM   #2
somebody@compusmart.ab.ca
 
Posts: n/a
Default Re: An odd case of email identity theft?

"Wha?" <> wrote:

>I maintain several different email accounts, although all through the same
>provider. Earlier today I got a "returned mail" message on one of my
>lesser-used accounts. It said that my email to some address I didn't know
>had permanent fatal errors blah blah blah... The weird part was that when I
>checked out the supposed original message, it was all in RUSSIAN... and in
>performing a whois trace, I saw that the domain of the target address was
>also RUSSIAN. Can anyone explain how this happens? Do I have to be
>concerned that someone has picked off access to one or all of my email
>accounts?


It could be a fake reurned e-mail.
http://membrane.com/security/compute...arvesting.html
http://www.lancs.ac.uk/iss/a-virus/falsesender.htm

You might want to change the password of the account in case somebody
did get in. And use strong passwords.

Roger
  Reply With Quote
Old 08-20-2003, 12:42 AM   #3
Jim Watt
 
Posts: n/a
Default Re: An odd case of email identity theft?

On Tue, 19 Aug 2003 17:34:46 -0400, "Wha?" <>
wrote:

>I maintain several different email accounts, although all through the same
>provider. Earlier today I got a "returned mail" message on one of my
>lesser-used accounts. It said that my email to some address I didn't know
>had permanent fatal errors blah blah blah... The weird part was that when I
>checked out the supposed original message, it was all in RUSSIAN... and in
>performing a whois trace, I saw that the domain of the target address was
>also RUSSIAN. Can anyone explain how this happens? Do I have to be
>concerned that someone has picked off access to one or all of my email
>accounts?
>
>Thx.


The previous crop of email worms mined the host machines email
address boof and used it to forge messages. If someone had your
address and sent out virus copies with it it could easily bounce
around. Also there was an attempt to infect people with forged
bounces.

**** happens, expect the unexpected. Constant change is here
to stay.
--
Jim Watt http://www.gibnet.com
  Reply With Quote
Old 08-20-2003, 02:37 AM   #4
Frank5
 
Posts: n/a
Default Re: An odd case of email identity theft?

On Tue, 19 Aug 2003 17:34:46 -0400, "Wha?" <>
wrote:

>I maintain several different email accounts, although all through the same
>provider. Earlier today I got a "returned mail" message on one of my
>lesser-used accounts. It said that my email to some address I didn't know
>had permanent fatal errors blah blah blah... The weird part was that when I
>checked out the supposed original message, it was all in RUSSIAN... and in
>performing a whois trace, I saw that the domain of the target address was
>also RUSSIAN. Can anyone explain how this happens? Do I have to be
>concerned that someone has picked off access to one or all of my email
>accounts?
>
>Thx.
>

I had the same problem. After changing passwords and investigation
with my email provider it turned out that my account had NOT been
compromised. Some spammer had used my rather plain email address as a
fake return address when sending out spam emails. The ones that went
to invalid addresses were bounced back to me. It stopped after a
couple of weeks.
  Reply With Quote
Old 08-20-2003, 03:37 AM   #5
Whoever
 
Posts: n/a
Default Re: An odd case of email identity theft?

On Tue, 19 Aug 2003, Wha? wrote:

> I maintain several different email accounts, although all through the same
> provider. Earlier today I got a "returned mail" message on one of my
> lesser-used accounts. It said that my email to some address I didn't know
> had permanent fatal errors blah blah blah... The weird part was that when I
> checked out the supposed original message, it was all in RUSSIAN... and in
> performing a whois trace, I saw that the domain of the target address was
> also RUSSIAN. Can anyone explain how this happens? Do I have to be
> concerned that someone has picked off access to one or all of my email
> accounts?
>

It's probably the latest version of the Sobig worm -- it forges the
sender email address. I've seen a few such returned mails today.

  Reply With Quote
Old 08-21-2003, 04:42 PM   #6
Mark
 
Posts: n/a
Default Re: An odd case of email identity theft?


"Jim Watt" <> wrote in message
news:...
>
> **** happens, expect the unexpected. Constant change is here
> to stay.
> --


Is that constant change going to be constant?


  Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump