01-12-2010, 19:47
|
#1
|
|
cf.mega poster
Join Date: Sep 2003
Location: Near Hungerford, West Berkshire
Services: TV: Sky HD, Landline: BT,
Mobile: Orange, Internet: Quite Slow!
Posts: 6,331
|
Spoofing Mails
Hi,
Today something strange happened.
My hotmail decided to send a spam message to my contacts and also to my messenger contacts.
I wasn't logged into either at the time.
So far I've changed my password and done complete virus scans and malware scans of my laptop and desktop - nothing found.
Any ideas how this happened? I can understand the email side of things but how the hell did it manage to send a msn message to my contacts when I wasn't even logged into msn!
__________________
Cheers,
Lee
Please take a look at my photography site and leave me some feedback.
|
|
|
01-12-2010, 19:48
|
#2
|
|
Catjack
Join Date: Jan 2009
Location: Liverpool
Services: Samsung V+ XL TV
XL Phone
30Mb Superhub
Nokia N8
Posts: 19,866
|
Re: Spoofing Mails
You do not need to be logged in if someone has managed to hijack your account, you have changed the password so it should be ok now.
__________________
"Religion was invented when the first con man met the first fool." - Mark Twain (1835 - 1910) now that has a ring of truth to it.
|
|
|
01-12-2010, 19:52
|
#3
|
|
cf.mega poster
Join Date: Sep 2003
Location: Near Hungerford, West Berkshire
Services: TV: Sky HD, Landline: BT,
Mobile: Orange, Internet: Quite Slow!
Posts: 6,331
|
Re: Spoofing Mails
OK thanks for that - is there a way to tell where it was logged in from like in gMail?
__________________
Cheers,
Lee
Please take a look at my photography site and leave me some feedback.
|
|
|
01-12-2010, 19:58
|
#4
|
|
Catjack
Join Date: Jan 2009
Location: Liverpool
Services: Samsung V+ XL TV
XL Phone
30Mb Superhub
Nokia N8
Posts: 19,866
|
Re: Spoofing Mails
I do not use or deal that kind of issue so maybe one of the more technical guys may be able to give advice.
I am basing this on Virginmedia webmail, I can be fully logged off this machine but my email can be accessed from virtually any machine in the world via the Virginmedia homepage as long as they have my email address and can crack my password, the first thing I would know about it would be when I noticed suspicious activity, such as strange emails dropping into my Outlook inbox.
__________________
"Religion was invented when the first con man met the first fool." - Mark Twain (1835 - 1910) now that has a ring of truth to it.
|
|
|
06-12-2010, 15:54
|
#5
|
|
Pete
Join Date: Jan 2004
Location: Nuneaton
Services: Broadband M ~ TV XL & V+ ~
Phone XL
Posts: 429
|
Re: Spoofing Mails
My daughter's Hotmail is always doing this, if anyone finds the answer, please post!
|
|
|
06-12-2010, 16:08
|
#6
|
|
Cable Forum Team
Join Date: Jun 2006
Services: Triple XL (BB 30Mb), TiVo, V+
Posts: 22,898
|
Re: Spoofing Mails
On gmail, at the bottom of the screen there is the option (Details) to check where your gmail has been accessed from
Quote:
Add your Gmail inbox to the Google homepage.
You are currently using 270MB (3%) of your 7527MB.
Last account activity: 32 minutes ago at IP xxx.xx.xx.xxx. Details
Gmail view: standard | turn off chat | turn off buzz | older contact manager | basic HTML Learn more
©2010 Google - Terms - Privacy Policy - Buzz Privacy Policy - Google Home
|
__________________
Just to make it clear if a post is bold and is from a team member, it's a moderating decision. If it's not bold or not from a team member, it's not.
|
|
|
06-12-2010, 16:27
|
#7
|
|
Catjack
Join Date: Jan 2009
Location: Liverpool
Services: Samsung V+ XL TV
XL Phone
30Mb Superhub
Nokia N8
Posts: 19,866
|
Re: Spoofing Mails
Quote:
Originally Posted by Hugh
On gmail, at the bottom of the screen there is the option (Details) to check where your gmail has been accessed from
|
If you do a NSLOOKUP of the ip address here I think you will find that is the email gateway for Googlemail.
This is mine on the Google platform Webmail 62.254.26.10 which resolves to
name = know-mailgateway-2.server.virginmedia.net.
__________________
"Religion was invented when the first con man met the first fool." - Mark Twain (1835 - 1910) now that has a ring of truth to it.
|
|
|
06-12-2010, 18:40
|
#8
|
|
Roooaaaarrrrr!!!
Join Date: Nov 2006
Location: Mercian Frontier
Age: 42
Services: Sidechaining
Posts: 3,716
|
Re: Spoofing Mails
The originating IP of the machine which sent the message will be in the header. Anyone can fake the contents of the "from" field, the level of difficulty in doing this is trivial.
There is a possiblity that someone you know has malware on their system which is harvesting their address book for valid contacts, using the addresses it finds as targets and also as values for the return address, yours being one of them.
__________________
Nero fiddles while Gordon burns... in his Joy Division oven gloves
|
|
|
06-12-2010, 20:53
|
#9
|
|
Cable Forum Team
Join Date: Jun 2006
Services: Triple XL (BB 30Mb), TiVo, V+
Posts: 22,898
|
Re: Spoofing Mails
Quote:
Originally Posted by Masque
If you do a NSLOOKUP of the ip address here I think you will find that is the email gateway for Googlemail.
This is mine on the Google platform Webmail 62.254.26.10 which resolves to
name = know-mailgateway-2.server.virginmedia.net.
|
You need to click on the details button to get the last ten ip addresses that accessed the account....
__________________
Just to make it clear if a post is bold and is from a team member, it's a moderating decision. If it's not bold or not from a team member, it's not.
|
|
|
06-12-2010, 22:54
|
#10
|
|
Catjack
Join Date: Jan 2009
Location: Liverpool
Services: Samsung V+ XL TV
XL Phone
30Mb Superhub
Nokia N8
Posts: 19,866
|
Re: Spoofing Mails
Quote:
Originally Posted by Hugh
You need to click on the details button to get the last ten ip addresses that accessed the account....
|
They are all email gateways just go to http://tools.virginmedia.com/ and put each of the 10 into it and do nslookup and they will all resolve to the email servers.
__________________
"Religion was invented when the first con man met the first fool." - Mark Twain (1835 - 1910) now that has a ring of truth to it.
|
|
|
07-12-2010, 09:41
|
#11
|
|
Cable Forum Team
Join Date: Jun 2006
Services: Triple XL (BB 30Mb), TiVo, V+
Posts: 22,898
|
Re: Spoofing Mails
Strange - when I check the IPs on the list, they resolve to my place of work, my mobile phone provider, and my home IP.......
__________________
Just to make it clear if a post is bold and is from a team member, it's a moderating decision. If it's not bold or not from a team member, it's not.
|
|
|
07-12-2010, 10:01
|
#12
|
|
Catjack
Join Date: Jan 2009
Location: Liverpool
Services: Samsung V+ XL TV
XL Phone
30Mb Superhub
Nokia N8
Posts: 19,866
|
Re: Spoofing Mails
Quote:
Originally Posted by Hugh
Strange - when I check the IPs on the list, they resolve to my place of work, my mobile phone provider, and my home IP.......
|
When I go to my @blueyonder.co.uk webmail account and I click on details at the bottom and then put them into nslookup they all resolve to an email gateway, but when I open my Googlemail accounts I cannot find the details button with the ip's listed.
__________________
"Religion was invented when the first con man met the first fool." - Mark Twain (1835 - 1910) now that has a ring of truth to it.
|
|
|
|
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
|
|
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT +1. The time now is 12:36.
|