Jul 25, 2008

[tutorial] About Spam/tracing E-mail & How To Avoid Spam

Free Web Hosting, No Ads > CONTRIBUTE > Computers > Computer Security Issues & Exploits

free web hosting

[tutorial] About Spam/tracing E-mail & How To Avoid Spam

tezza
QUOTE
Using a case study of a e-mail I got, it's not really spam but its sort of.

The first rule is NEVER reply to spam, NEVER click the unsubscribe link and NEVER e-mail to the unsubscribe address.

These are simply underhand tactics to get 'active' e-mail addresses.

Some other tips to avoid getting spammed in the first place:

1) Never use your real e-mail address in newsgroups, this is the best place to get picked up by a spam bot. Use something like john-no-spam-at-i.hate.spam-btopenworld.com

Then in your signature put remove -no-spam and i.hate.spam- to reply.

2) Never put your e-mail address on a publically viewable web page as it will be spidered by Google and grabbed by spammers.

If you do need to put an e-mail address use the simple JavaScript below to protect it:

Code:

<!-- Begin Shaolin Tiger E-mail Saver

randomword = "john";
randomword2 = "btopenworld";
append = "?Subject=Enquiry&Body=Please%20Insert%20Your%20Message%20Here.";

document.write('<a href=\"mailto:' + randomword + '@' + randomword2 + append + '\">');
document.write(randomword + '@' + randomword2 + '</a>');
// End -->
</SCRIPT>



3) If you do put your e-mail address anywhere try and obscure it in some way.

4) Create a disposable e-mail address (hotmail or yahoo) that you rarely check for signing up to Web-sites. Most commercial sites will bombard you with spam after you've signed up for whatever services they are offering. Some also sell your address to list makers or other spammer so never give your *real* e-mail address to anyone except people you want to e-mail you.

If you follow all of these you wont get any spam. My yahoo account which I made when I was internet Naive gets about 20-30 spams a day, this is just from signing a few guestbooks with my real e-mail address and putting it on my first home page.

Now I follow the above rules, I don't get any

If you do get some, follow below:

In this example youremail-at-yourdomain.com = Your e-mail address.

Find the full headers of the message, headers can be found in the message source in Outlook Express.

Headers look like this:

Code:

Return-Path: <nobody-at-letters.ezinehub.com>
Delivered-To: securityforumsco-admin-at-127.0.0.1
Received: (qmail 94940 invoked by uid 1373); 2 May 2002 20:16:38 -0000
Delivered-To: youremail-at-yourdomain.com
Received: (qmail 94937 invoked from network); 2 May 2002 20:16:37 -0000
Received: from unknown (HELO letters.ezinehub.com) (64.23.12.74)
by ns1.dc-hosting.net with SMTP; 2 May 2002 20:16:37 -0000
Received: (from nobody-at-localhost)
by letters.ezinehub.com (8.11.6/8.9.3) id g42KKTr28012;
Thu, 2 May 2002 16:20:29 -0400
Date: Thu, 2 May 2002 16:20:29 -0400
Message-Id: <200205022020.g42KKTr28012-at-letters.ezinehub.com>
To: youremail-at-yourdomain.com
From: support-at-exactseek.com
Subject: Important ExactSeek site listing information.



The main things you want to look for are:

1) The e-mail address it originated from (Most likely spoofed)

From: support-at-exactseek.com

2) The server used to send it (Most likely an open relay)

by letters.ezinehub.com (8.11.6/8.9.3) id g42KKTr28012

3) The IP address it originated from (Usually unspoofed, often encoded or hidden)

(HELO letters.ezinehub.com) (64.23.12.74)

In this case as this resulted from a search engine submission the SMTP server and the senders IP are the same.

Generally they would be different.

The next stage is to find the upstream provider of the SMTP server and the originating IP. Also take note of the domain the e-mail appeared to come from.

For this we would use Sam Spade or something similar.

If you are using Win2k you can just use tracert (Trace Route) from the command line.

As Samspade is down for maintenance at the moment I will use tracert in this example.

Result of tracert on letters.ezinehub.com

1 160 ms 160 ms 161 ms 194.176.218.67
2 240 ms 181 ms 140 ms 194.176.218.242
3 161 ms 180 ms 160 ms 194.176.218.43
4 160 ms 160 ms 180 ms 194.176.220.189
5 160 ms 160 ms 160 ms sl-gw10-lon-8-0.sprintlink.net [213.206.130.9]
6 160 ms 160 ms 161 ms sl-bb21-lon-8-0.sprintlink.net [213.206.128.45]
7 220 ms 241 ms 240 ms sl-bb20-msq-10-0.sprintlink.net [144.232.19.69]
8 340 ms 240 ms 241 ms sl-bb20-rly-15-1.sprintlink.net [144.232.19.94]
9 240 ms 241 ms 240 ms sl-gw19-rly-9-0.sprintlink.net [144.232.14.26]
10 240 ms 241 ms 240 ms sl-affinity-11-0-0.sprintlink.net [160.81.221.150]
11 240 ms 240 ms 241 ms core2a.balt.skynetweb.com [208.231.4.4]
12 241 ms 240 ms 240 ms ezinehub.com [64.23.0.31]

As can be seen the upstream provider is sprintlink.net and the web host most likely skynetweb.com.

This should be repeated for the provider of both the originating IP address and the SMTP server used.

The next step is to e-mail all of these people using the e-mail I constructed below:

ShaolinTiger wrote:


The following COMMERCIAL UNSOLICITED E-MAIL was received by myself at the non-published, non-used address sent to youremail-at-yourdomain.com. Please educate your users that this spam and can clog people's mailboxes and subject them to criminal prosecution.

In some states, it falls under the definition of illegal faxing without the recipient's permission. (Device having a computer, modem, and printer and capable of printing images. USC 47.5.II.227. Fine: $500 per recipient.)

In some countries, notably England, it falls under the Criminal Statutes regarding unauthorized alteration of computer data or theft of computer resources. (Theft of access time and disk space.)

Anyone affiliated to this person and/or company can be held responsible as an ACCESSORY to these CRIMINAL ACTIONS!

EDUCATE your Users or cut them off at the phone line!




E-mail this to abuse@, spam@, postmaster@ all the ISP's/Web-hosts/Services providers you identified using traceroute or Samspade.

E.g. in this case abuse-at-sprintlink.net; spam-at-sprintlink.net etc.

Include the full e-mail with full headers, proof of traceroutes and so on.

Stop the spammer, they are wasting everyones bandwidth.

I will update this document whenever I think of something to add to it, or something new comes up.

Any comments/suggestions are welcome and if you don't understand any of it ask and I will clarify.


Notice from serverph:

 

 

 


Reply

Zero Ziat
http://gishpuppy.com beats you heavily to the floor with a big hammer. XD

It helps more than expected when signing up.

Reply



Got an Opinion! Express your Views! (no registration):-
Add your Reply/ Opinion/ Views/ Comments/ Suggestion/ Questions/ Queries etc.
Posts with decent grammar & English will be accepted and please refrain from profanities.
For asking a Question, We recommend you to sign-up (for free) so that you can track the topic easily.

Nature of your Post*: Opinion/ Reply/ Comments
Question/Query
Feedback to us.
       
Name   Email
Title/Question*

(Maximum characters: 10,000)
You have characters left.
Confirm Code:

Recent Queries:-
  1. how to avoid spam emails - 31.49 hr back. (1)
Similar Topics

Keywords : spam, tracing, e, mail, and, avoid, spam

  1. Fight Spam Email
    Link to this script on your Hosting Account (0)
  2. Free And Easy Ip Tracing
    This is amazing and free (10)
    Found this technique recently, I am new to trap 17 so apologies if this is handled elsewhere. on
    win xp go to start and run 'cmd' at command prompt, type. 'tracert
    www.nameofwebsite.com' you should then get a list of ip addresses starting with your own back
    to that of the web address you typed in. If you then wish to trace the geographic location, go to
    www.ip-address.com, type in the ip address and a google map showing the location of the server will
    soon appear. Obviously if you or the target are disguising or hiding the ip address it may not be s....
  3. E-bay Phishing E-mail Still Out There
    Watch your privacy (3)
    This e-mail has been going around for a while now. I've recieved it about 5 times now. I
    thought e-bay would be on it like hawks but there really isn't much they can do about it. Just
    be aware of your personal information. Subject: eBay Account Verification Date: Fri, 20 Jun
    2003 07:38:39 -0700 From: "eBay" Reply-To: accounts@ebay.com To: Dear eBay member, As part
    of our continuing commitment to protect your account and to reduce the instance of fraud on our
    website, we are undertaking a period review of our member accounts. You are requested to v....
  4. Stopping Spam And Its Effects!
    (0)
    Stopping SPAM and its effects ----------------------------------- SPAM or unsolicited mail usually
    comes to your mailbox from 'anonymous' sources. They are most frequently as a result of you
    giving out your address on a site. But your mail providers (usually) work very hard to stop these
    kind of messages from clogging your limited() space. There aer many things about that, but we
    won't get into those. The thing Yahoo is using right now is Yahoo's DomainKeys. Read more
    about the technical details here. Here's the effects of this system... 1) Most o....
  5. Using Your Email To Send Spam
    What exactly do they call those things? (10)
    I was happily browsing the web so I decided to check my Yahoo! email. I got like 4 emails that
    were bounced back by Mail-Daemon. Apparently, I had tried to send this spam mail to some MSN
    groups!? It was bounced back to me because I had to be a member of that group to send emails.
    (Whew!) /blink.gif" style="vertical-align:middle" emoid=":blink:" border="0" alt="blink.gif" />
    I was shocked and ran all the scans I could think of (Adware/Anti-virus) and deleted this Cydoor
    adware. I'm not sure that was what caused it, and I'm starting to freak out, beca....
  6. Bluesecurity
    Anti spam blablabla (1)
    BlueSecurity advertises itself as a method to counter-act spam, today I received an email, which
    looks very suspicious (Which isnt from BlueSecurity btw). Has anyone received an email like this as
    well? I already de-installed BlueSecurity ages ago because the program made my Firefox crash very
    often, but emails like this make me scared, really scared. Seeing they can obtain my email because
    I'm signed up for BlueSecurity, I wonder what spammers would and also could, do with it.
    QUOTE She was coming down the hallway now.One was suspending something (the typewrite....
  7. Weird E-mail I Got Sent
    Take a Look, it's a scam, for sure (2)
    Look at that, scammers, trying to make some "cash". Whenever you get an email sent like this,
    it's scam for sure. I didn't even sign up for anything, or gave my e-mail away, and I get a
    coupld hundred thousand (in euros). I doubt it. What pure scam...I reported this to Yahoo!.
    QUOTE PAYDAY INTERNATIONAL LOTTERIA Ref : GW/06-AT/4273 Batch: GW/06/7676 We are pleased to
    inform you of the result of the just concluded annual final draws of Payday International Lotteria
    Program.Payday International Lotteria draws was conducted from an exclusive list of 2....
  8. Yahoo! Mail Warns Me, Please Help
    *DETECTED* Online User Violation (true?) (38)
    I'm receiving the folloing quoted messages from mail@yahoo.com with zip file as an attachment. I
    am quite disturbed with the message. Could this message be true Or should I ignore it? As far as my
    knowledge is concerned I have never sent any spam messages using my yahoo mail account. And I hate
    spam messages too. What if they eventually close down my yahoo email ID!! /sad.gif'
    border='0' style='vertical-align:middle' alt='sad.gif' /> Does anyone get the same message? The
    thing is that this mail reaches to my Junk mailbox too. Please give your opinion!....
  9. Avoid Dao Search
    Virus, Adware, and Spyware (4)
    Recently well surfing, I was infected with a program that secretly downloaded itself called DAO
    Search. It started to generate many popups, messing up some programs, and changed all common words
    on every webpage into search links (even if they were links already.) And it would replace Domain
    Names with IP addresses. It Hijacked Internet Explorer and Netscape. And everytime it is removed it
    will re-download itself. If You Come accross this you will have to run an Anti-Spyware Program and
    clean it and its registry keys, then search your computer for DAO, a Dll file s....
  10. ? Doesn't G-mail Notifier Work Wit Firefox?
    ??Why?? (15)
    Does anyone know ? g-mail Notifier doesnt work on Firefox? It doesnt log u in it jus takz u 2 tha
    login PG. Do u know ?. I accually work @ Google so its embarrasin askin hre. ....
  11. Paypal Scam Spam
    Warning, beware of emails as such... (13)
    Well, I could not post a screenshot because I already deleted the email. I don't own a paypal
    account but i got an email saying that my account could become permanently inactive if i don't
    update the details. I was directed to this site ( http://203.162.1.205/support/support.asp) -
    Don't enter anything. It looks really professional and secure but it's just a phishing
    attempt, gmail even warned me. It asked me for my credit card number. Emails like these really
    piss me off. This is just a warning to those of you. Btw, like microsoft scam emails yo....

    1. Looking for spam, tracing, e, mail, and, avoid, spam

Searching Video's for spam, tracing, e, mail, and, avoid, spam
advertisement



[tutorial] About Spam/tracing E-mail & How To Avoid Spam



 

 

 

 

ADD REPLY / Got an Opinion! Remove these ADs! RAPID SEARCH! Free Web Hosting [X]
Express your Opinions, Thoughts or Contribute more info. to help others.
Ask your Doubts & Queries to get answers, So that "Together We can help others!"
Register FREE for AD-FREE forum, Create your own topics, Ask Questions, track topics, setup subscriptions & notifications and Get a Free Website w/ Email and FTP.
500MB Space *No Ads*, CPanel, FTP, PHP, MySQL, EMails - 100% FREE