Home News Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | john@ntlworld.com


You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Virgin Media Services > Virgin Media Internet Service > Webspace, E-Mail & Browsing Issues

john@ntlworld.com
Reply
 
Thread Tools
Old 10-12-2003, 17:26   #1
gary_580
Guest
 
Posts: n/a
john@ntlworld.com

Anyone else get a whole bunch of emails from john@ntlworld.com sent to their ntlworld email account?

My anti virus software went made when these were coming down the wire.
  Reply With Quote
Old 10-12-2003, 17:31   #2
Sociable
Inactive
 
Sociable's Avatar
 
Join Date: Jun 2003
Location: Knebworth
Age: 59
Posts: 1,816
Sociable has entered a golden reputation eraSociable has entered a golden reputation eraSociable has entered a golden reputation eraSociable has entered a golden reputation eraSociable has entered a golden reputation eraSociable has entered a golden reputation eraSociable has entered a golden reputation eraSociable has entered a golden reputation eraSociable has entered a golden reputation eraSociable has entered a golden reputation eraSociable has entered a golden reputation era
Re: john@ntlworld.com

Nope but it's not uncommon for the "Ghost" sender's name to be something that sounds "OK" like "John" as it increases the chance of those who do get mail from a real "John" to be tempted to open with less thought.
Sociable is offline   Reply With Quote
Old 10-12-2003, 18:34   #3
Jon M
Inactive
 
Jon M's Avatar
 
Join Date: Oct 2003
Location: Bracknell
Age: 34
Services: Freeview, NTL phone, NTL 4mbit BB SACM
Posts: 3,281
Jon M has a bronze arrayJon M has a bronze arrayJon M has a bronze array
Jon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze array
Send a message via MSN to Jon M
Re: john@ntlworld.com

same as sociable said, plus..

as a general rule the sender address is worthless when tracing spam or virii, it's the IP address in the header that gives you the actual source
Jon M is offline   Reply With Quote
Old 11-12-2003, 00:01   #4
gary_580
Guest
 
Posts: n/a
Re: john@ntlworld.com

i got a load more tonight. The ip address is 80.0.208.185.
  Reply With Quote
Old 11-12-2003, 13:38   #5
Dooby
Inactive
 
Join Date: Jun 2003
Posts: 285
Dooby is on a distinguished roadDooby is on a distinguished road
Re: john@ntlworld.com

that resolves to
public2-pete1-3-cust185.lond.broadband.ntl.com

so it looks like an ntl ip.

I would say that it would also be possible to spoof the IP address of the sender too, more difficult, but possible
Dooby is offline   Reply With Quote
Old 11-12-2003, 15:14   #6
gary_580
Guest
 
Posts: n/a
Re: john@ntlworld.com

so basically your saying its not possible to trace this email back ot the originator?
  Reply With Quote
Old 11-12-2003, 15:35   #7
danielf
cf.mega poser
 
danielf's Avatar
 
Join Date: Jun 2003
Posts: 14,312
danielf has a lot of silver blingdanielf has a lot of silver blingdanielf has a lot of silver blingdanielf has a lot of silver blingdanielf has a lot of silver blingdanielf has a lot of silver blingdanielf has a lot of silver blingdanielf has a lot of silver bling
danielf has a lot of silver blingdanielf has a lot of silver blingdanielf has a lot of silver blingdanielf has a lot of silver blingdanielf has a lot of silver blingdanielf has a lot of silver bling
Re: john@ntlworld.com

Quote:
Originally Posted by gary_580
so basically your saying its not possible to trace this email back ot the originator?
If you post the full headers (removing your email address), it is possible to trace the origin, but it may well turn out to be an open relay somewhere in China.
__________________
Gimme back my dog.
danielf is online now   Reply With Quote
Old 11-12-2003, 15:43   #8
Sociable
Inactive
 
Sociable's Avatar
 
Join Date: Jun 2003
Location: Knebworth
Age: 59
Posts: 1,816
Sociable has entered a golden reputation eraSociable has entered a golden reputation eraSociable has entered a golden reputation eraSociable has entered a golden reputation eraSociable has entered a golden reputation eraSociable has entered a golden reputation eraSociable has entered a golden reputation eraSociable has entered a golden reputation eraSociable has entered a golden reputation eraSociable has entered a golden reputation eraSociable has entered a golden reputation era
Re: john@ntlworld.com

Quote:
Originally Posted by gary_580
so basically your saying its not possible to trace this email back ot the originator?
Not with any degree of certainty no.

It is possible to spoof the originating IP and even if it did originate from that IP it may well not have been the person on that IP that initiated it. If that person has a trojan sitting on their system it would be relatively simple to bounce mails through them without them ever being aware of it.

Going back a few years Cabletel (Pre NTL) were blacklisted by many sites because their mail servers were so insecure they were a popular target for this type of "Bounce" being used to hide the true origins of attacks. Up-dates to the security allowed them to get off the blacklist but it shows just how easy it can be to fool the system even when it is being controlled by a large organisation in the internet provison field let alone an individual subscriber.
Sociable is offline   Reply With Quote
Old 12-12-2003, 14:08   #9
gary_580
Guest
 
Posts: n/a
Re: john@ntlworld.com

Got some more today. This is the complete header

Return-Path: <john@ntlworld.com>
Received: from localhost ([80.0.208.185]) by mta07-svc.ntlworld.com
(InterMail vM.4.01.03.37 201-229-121-137-20020806) with SMTP
id <20031212072431.BIQ2588.mta07-svc.ntlworld.com@localhost>
for <****.*****@ntlworld.com>; Fri, 12 Dec 2003 07:24:31 +0000
From: john@ntlworld.com
To: ****.***** <****.*****@ntlworld.com>
Reply-To: john@ntlworld.com
X-Priority: 1 (High)
Subject: don't be late! aeaagmeg
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="----------D5017952000A9B8"
Message-Id: <20031212072431.BIQ2588.mta07-svc.ntlworld.com@localhost>
Date: Fri, 12 Dec 2003 07:24:36 +0000
  Reply With Quote
Old 12-12-2003, 16:05   #10
hoss
Inactive
 
Join Date: Sep 2003
Location: by 'ere
Posts: 8
hoss is an unknown quantity at this point
Re: john@ntlworld.com

Try forwarding a couple of headers to abuse@ntlworld.com, I would have thought that they should be able to tell him to stop spamming you (assuming the header hasnt been spoofed) or to protect himself from trojans
hoss is offline   Reply With Quote
Old 12-12-2003, 20:56   #11
Indians
Inactive
 
Indians's Avatar
 
Join Date: Nov 2003
Location: Grimsby
Posts: 199
Indians is a glorious beacon of lightIndians is a glorious beacon of lightIndians is a glorious beacon of lightIndians is a glorious beacon of lightIndians is a glorious beacon of lightIndians is a glorious beacon of lightIndians is a glorious beacon of light
Re: john@ntlworld.com

I got a boatload of these in a BTINTERNET email account last week, from a 'john@btinternet' same subject line as yours 'don't be late!' followed by a series of letters that were different on each email. Body of message was something about 'see you on wednesday' etc 'details in attached file' , which was a .zip file containing a .scr file. D
I deleted them all but would have been interested to find out what the script did.
Indians is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



Google Search




All times are GMT +1. The time now is 14:14.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
Copyright © 2003 - 2012, Cable Forum.
(server1.cableforum.co.uk)

SEO by vBSEO 3.3.2