Computing.Net > Forums > Security and Virus > email spoofing

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

email spoofing

Reply to Message Icon

Name: balloonfiesta
Date: June 13, 2006 at 11:32:34 Pacific
OS: xp media centre 2002
CPU/Ram: pentium 4 3ghz 512 ram
Product: hp pavilion
Comment:

I have my own website and have been getting spoof emails sent to me as if they are from someone in my own comapny using balloonfiesta.tv as the domain.
Can anyone advise if there is any way to overcome this problem.
Any help would be most grateful.



Sponsored Link
Ads by Google

Response Number 1
Name: don2006
Date: June 13, 2006 at 16:53:38 Pacific
Reply:

Are the headers spoofed as well? If the IP addresses aren't spoofed, then you maybe able to find where they originate and alert the ownners of the server. They could be using an opened relay.
If that's not possible, you make be able to filer it.


0

Response Number 2
Name: balloonfiesta
Date: June 14, 2006 at 00:37:26 Pacific
Reply:

Hi Don2006,

Thanks for replying.

These were the properties of the email I received.

As I am relatively new to this game, I am not sure what all this means.

My main concern is not that I am receiving Spam (I have NIS2006 which filters it very well), but that some unscrupulous individual has managed to register an email address within my domain,how this is possible and how can I prevent it from happening.

Any help would be greatly appreciated.

Return-Path: <QMhjWD@balloonfiesta.tv>
X-Original-To: paul@balloonfiesta.tv
Delivered-To: balloonfiesta@godzilla.bigwig.net
Received: from PCUSNJRNST2 (unknown [216.169.212.5])
by godzilla.bigwig.net (Postfix) with SMTP id 142411FE57
for <paul@balloonfiesta.tv>; Tue, 13 Jun 2006 18:01:49 +0100 (BST)
Received: from [73.238.103.212] (port=9204 helo=[73.238.103.212])
by balloonfiesta.tv with esmtp
id woekgg-gOz837-26
for paul@balloonfiesta.tv; Tue, 13 Jun 2006 11:25:43 +0600
Reply-To: Jerry <QMhjWD@balloonfiesta.tv>
Message-ID: <46132265.20060613112543@balloonfiesta.tv>
From: Jerry <QMhjWD@balloonfiesta.tv>
To: <paul@balloonfiesta.tv>
Subject: Never better cant be fOund.
Date: Tue, 13 Jun 2006 11:25:43 +0600
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="----=_NextPart_000_0068_01C4B064.23976819"
X-Priority: 1
X-Mailer: The Bat! (v3.71.14) Home
X-Spam: Not detected
X-NAS-Language: Dutch
X-NAS-Bayes: #0: 8.14301E-056; #1: 1
X-NAS-Classification: 0
X-NAS-MessageID: 3095
X-NAS-Validation: {2D1C135D-0BB2-4F23-AF1C-9F28A26FB2F5}

Many thanks,

Paul.


0

Response Number 3
Name: seawatch
Date: June 14, 2006 at 09:30:15 Pacific
Reply:

WhoIs Lookup performed by Karen's WhoIs
http://www.karenware.com/

OrgName: Novo Nordisk Pharmaceutical, Inc.
OrgID: NNP-4
Address: 100 college road west
City: Princeton
StateProv: NJ
PostalCode: 08540
Country: US

NetRange: 216.169.208.0 - 216.169.223.255
CIDR: 216.169.208.0/20
NetName: NNPI-COM
NetHandle: NET-216-169-208-0-1
Parent: NET-216-0-0-0-0
NetType: Direct Assignment
NameServer: T.NS.VERIO.NET
NameServer: B.NS.VERIO.NET
Comment:
RegDate: 2004-06-16
Updated: 2004-06-16
RTechHandle: AHO21-ARIN
RTechName: Ho, Antien
RTechPhone: +1-609-987-5876
RTechEmail: atnh@novonordisk.com

RTechHandle: MRU9-ARIN
RTechName: Ruggiero, Matt
RTechPhone: +1-609-987-7787
RTechEmail: mrgg@novonordisk.com

OrgTechHandle: AHO21-ARIN
OrgTechName: Ho, Antien
OrgTechPhone: +1-609-987-5876
OrgTechEmail: atnh@novonordisk.com

OrgTechHandle: MRU9-ARIN
OrgTechName: Ruggiero, Matt
OrgTechPhone: +1-609-987-7787
OrgTechEmail: mrgg@novonordisk.com

# ARIN WHOIS database, last updated 2006-06-13 19:10
# Enter ? for additional hints on searching ARIN's WHOIS database.

Today seems like a good day to chew through the restraints.


0

Response Number 4
Name: km3161
Date: June 14, 2006 at 14:57:57 Pacific
Reply:

http://home.att.net/~marjie1/usenet.htm


0

Response Number 5
Name: don2006
Date: June 15, 2006 at 16:58:23 Pacific
Reply:

He didn't register an email address in your domain. Anyone can put any email address in the return line and the server will use it and give it a message ID.

Received: from [73.238.103.212] (port=9204 helo=[73.238.103.212])

That's the key line in the header for 2 reasons. one the helo, which is the first command used when using an opened relay. Sometimes the server wants you to say helo, believe it or not. The second thing is the port number 9204, which denotes a wireless connection. The message could have even been sent from a cell phone. There is probably more but that's as far as I researched it.

To answer your question as to how to stop it, you probably just have to create a filter blocking those IP addresses which may or may not work. I'm sure there are other unsecured connections available.


0

Related Posts

See More



Response Number 6
Name: balloonfiesta
Date: June 16, 2006 at 08:30:52 Pacific
Reply:

Many thanks to all who have helped me, and I will follow up all cmments and suggestions.

Paul.


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: email spoofing

Email spoofing www.computing.net/answers/security/email-spoofing/3699.html

A Virus in My eMail? www.computing.net/answers/security/a-virus-in-my-email/14132.html

PC-Cillin doesn't detect virus/worm www.computing.net/answers/security/pccillin-doesnt-detect-virusworm/3119.html