What to do when a hacker uses your email [Archive] - Ceramic Tile Advice Forums - John Bridge Ceramic Tile

PDA

View Full Version : What to do when a hacker uses your email


Bill Vincent
02-26-2005, 08:33 AM
I checked my email yesterday, and got a mailer-daemon notice that an email had failed, and it was spam about CHILD PORN!! I went in, changed my password and security question, and tried to contact Hotmail, but couldn't send the message in-- kept getting a "can't find page" window. So, I kept it up on my computer till this morning and I figured I'd send it in now. Well, I just got on my computer, and even after changing the password and question, THERE WAS ANOTHER MAILER-DAEMON NOTICE!! It's bad enough when this happens with normal spam, but this, to me, is about as sick as it gets, and on top of that could get me in alot of trouble, and I'm not sure what I should do-- if I should contact authorities (WHICH authorities), or WHAT!!

Sponsored Links


HDtilegrunt
02-26-2005, 08:41 AM
I would certainly contact the authorities about that. Certainly better than them contacting you and they may be able to track down at least how it is being routed through you. Pretty scary and sick. Too bad for you. Imagine if it used your address book and sent these emails to all the people you've helped before. You've never been shy about posting your email addy and I'm sure it fills up all the time. In the mean time, if you cannot contact Hotmail, I'd be happy to do it on your behalf.

HDtilegrunt
02-26-2005, 08:54 AM
I'd also suggest you download and run Spybot and Adaware to check for and remove any dialers or bckdoors or other garbage that may be on your computer. After you download them, restart your computer in "safe mode" by holding down the f8 key at start up and run the programs in safe mode so they will be able to remove more items. Alot of this crap piggybacks onto other programs and having an absolute minimum amount of stuff running when using the programs will allow in to remove more. If you run IE, download and install Mozilla Firefox which is not as corruptable as IE. Does anyone know of any free firewall programs out there that are any good? Might want one of them too.

davem
02-26-2005, 08:58 AM
Are you sure it's a real email from Hotmail? It could be a scam.

There are a lot of spam emails that are designed to look genuine. They tempt people to click on a link within them and enter things like username and passwords. I get one all the time that looks like it's from PayPal, but it you look carefully the links in the email don't really go to the PayPal site.

Bill Vincent
02-26-2005, 09:05 AM
Here are the two failure notices I got:

From : <MAILER-DAEMON@email3.peakpeak.com>
Sent : Friday, February 25, 2005 4:25 PM
To : billvincent@hotmail.com
Subject : failure notice

| | | Inbox


Hi. This is the qmail-send program at email3.peakpeak.com.
I'm afraid I wasn't able to deliver your message to the following addresses.
This is a permanent error; I've given up. Sorry it didn't work out.

<bkamps@peakpeak.com>:
./Maildir/.Spam/ Sorry, no mailbox here by that name. (#5.1.1)

--- Below this line is a copy of the message.



From: Twosome F. Allows <billvincent@hotmail.com>
Reply To: amm2@bellsouth.net
To: Bkamps <bkamps@peakpeak.com>
Subject: Bkamps, exclusive C_P_ site, 25/02/05
Sent: Friday, February 25, 2005 8:01 AM
Hello ! We open new exclusive Ch1ld P0rn0 website. Limited time offer. We will accept new signups only 1 week. What we have: - More than 10,000 CP hardcore photos and movies! - New photos every week! - More than 20 categories in each sites! - All photos are high quality! - We never cheat our users, we give you only what you want! - All photos are exclusive! - View free preview now



From : Mail Delivery System <MAILER-DAEMON@mx2.vistabroadband.net>
Sent : Saturday, February 26, 2005 9:43 AM
To : billvincent@hotmail.com
Subject : Undelivered Mail Returned to Sender

| | | Inbox


This is the Postfix program at host mx2.vistabroadband.net.

I'm sorry to have to inform you that the message returned
below could not be delivered to one or more destinations.

For further assistance, please send mail to <postmaster>

If you do so, please include this problem report. You can
delete your own text from the message returned below.

The Postfix program

<sdgsdg@ava.com>: host mx1.vistabroadband.net[206.176.240.47] said: 550
sdgsdg@ava.com unknown user account (in reply to RCPT TO command)



From: Gallagher D. Glimpse <billvincent@hotmail.com>
Reply To: mik1985_us@yahoo.com
To: Sdgsdg <sdgsdg@ava.com>
Subject: Sdgsdg, exclusive C_P_ site, 25/02/05
Sent: Saturday, February 26, 2005 1:48 AM
Hello ! We open new exclusive Ch1ld P0rn0 website. Limited time offer. We will accept new signups only 1 week. What we have: - More than 10,000 CP hardcore photos and movies! - New photos every week! - More than 20 categories in each sites! - All photos are high quality! - We never cheat our users, we give you only what you want! - All photos are exclusive! - View free preview now






If you notice, there are no links, which really strikes me as strange.

Bill Vincent
02-26-2005, 09:15 AM
I just did a spyware scan, and it found 25 spyware items, 24 of which it said can be disabled without screwing up any programs. It didn't tell me, however, what the 25th was and what can be done about it.

It's unbelieveable how much faster this puter is now, too-- almost as fast a my wife's on broadband!!

jgleason
02-26-2005, 09:15 AM
These are bounce messages from email servers that are rejecting messages, supposedly sent by you, due to being sent to unknown recipients or because of content, i.e. - spam. Unfortunately, there isn't a lot you can do. The "From" address of an email is quite easy to spoof. I can, if I wanted to, easily send any email I want out to folks with ANY "from" address I choose.

Why your email address? Easy, if it is posted anywhwere on the web or in someone else's email address book, it can be picked up and used by any number of trojans, backdoor programs, etc.

Bill Vincent
02-26-2005, 09:17 AM
So, in other words, either I stop helping folks and go on my merry way, or I live with it?

Fant
02-26-2005, 09:19 AM
Bill, There is a good chance that there is nothing wrong on your system. There are lots of viruses and mail worms that harvest email addresses from an inbox and then use them as from addresses on spam or other email the worm sends. That is to say that anyone that you have sent email to may have had a virus and that is how your email address got used for this.
I would still do all the scans mentioned. I would contact whomever you think you need to including your email provider (it looks like hotmail) and let them know what is going on. There is a good chance that this will pass after a little while.
If you are really worried about this then you might consider changing your email address. Changing can be a real pain, but might be worth it.

At work we have had all kinds of "returned" emails using our company IDs as the from address. The fact that you have sent email to anyone can expose you to this kind of attack.

One trick I have seen when posting your address or giving it to people is to make it understandable by people but not by computers when you pase out the address. For example an email adress of joe@domainname.com I have seen people write it as joe at domainname_com and replace the _ with .

This is a pain as well, but will help protect your address somewhat for tools that scan forums and places looking for this@that.com format.

Good luck with this.

Albert
02-26-2005, 09:21 AM
Bill, I agree that it is probably someone inserting your e-mail address as the return address. When the receiving person marks it as spam it is bounced back to you, b/c that is the return address. I've had it happen to me before and it makes me furious, but I don't think there is anything you can do short of changing your e-mail address. The crooks should be coated in Keralastic, rolled in cutback, have their nostrils packed with mortar, and thrown in jail.

albert

Bill Vincent
02-26-2005, 09:26 AM
Fant-- I'll try that-- with posting my email a little differently. The LAST thing I want to do is change my email address. I will if necessary, but I've had this email since I got on line 7 years ago (which is how I was able to get my name without numbers or any kind of fancy doodads), and I'd rather not lose it if possible.

Albert-- THESE crooks in particular should have their bags cut off and stuffed down their throats, and I'd love to be the one to do it. This is some sick crap!! NOTHING infuriates me more than hurting kids in ANY way!!

Shaughnn
02-26-2005, 09:37 AM
Bill,
It's also possible that your e-mail address was "harvested" from any of the forums or mail groups you post to. I moderate a couple of yahoo groups and I've had to deal with such annoyances until I restricted membership to my approval. To my knowledge, no one of the members have been targeted through these groups since.
Best of luck,
Shaughnn

davem
02-26-2005, 09:37 AM
I agree with the comments you've gotten. One thing I do is keep a yahoo address that I give out somewhat freely. I consider it disposable. My main address (that I really don't want to get abused) is never posted where it can be seen on the web.

When I need to supply an email addy to someone I know I don't trust, I use a disposable from spamgourmet http://www.spameater.org/ . It's really cool, you can make up email addresses on the fly that will only be valid a certain number of times. They get forwarded to your main address up to 20 times and after that they just get thown away. You can have an email conversation with someone and they never know your real address. :)

DIYOHMY
02-26-2005, 09:57 AM
I would consider it junk email and delete it without opening. All it means is that someone may have tried to send mail through your mail server, but failed. Your computer and email account may not even have been involved. If you get a lot more of the same thing, contact your isp, otherwise, ignore it.

I imagine that if someone around here saw an email titled "New Porn from Bill Vincent", they'd let you know. So chances are you are safe :nod:

Bill Vincent
02-26-2005, 10:03 AM
Shaughnn-- My wife had to do the same thing-- she has several yahoo groups having to do with fashion doll makeovers and crocheting, and started out with the groups all being open membership untill someone started spamming with several of the members' emails, and between that and "trolls", she ended up having to restrict access to registered members only and change her email address. I'm HOPING I don't have to go that route.

Dave, I've got the same thing-- my hotmail, a yahoo addy, as well as my server based email, and in retrospect, I probably should have used a different email for giving out in the forums, and I will most likely set up another email just for this purpose now, I just hope it's not too late.

DIYOHMY-- I probably will, but I'm going to wait for hotmail to get in touch with me, first. I'd like to put a stop to my email addy being used, but even more, I'd like, if possible to trace down these sick bastards and put em out of business. If hotmail can't do anything about it, I may contact either the local police or fbi to see if there's anything in these emails that could help them.

tileguytodd
02-26-2005, 10:07 AM
Thats a cool site Dave.Why didnt you think this one up?? ;)

davem
02-26-2005, 10:20 AM
Go ahead and spam me at nofear.2.tg734@spamgourmet.com . It will only work 2 times! :)

jdm
02-26-2005, 12:20 PM
Bill --

I'lll bet this whole thing was dreamed up by some lonely high school geek who just wanted to rattle some cages. Since there is no way for interested sickos to find the supposed website, I doubt that there is one at all. I wouldn't worry about the authorities, either. They know how easy it is to get tricked into surfing to a website, and according to a recent newspaper article about breaking up a child porn ring, took pains to determine who accidentally got to a site from those who were really involved.

And from what I understand, following Fant's advice to disguise your address from harvesting programs really helps. Some would go further to make it
bill removethis vincent at hotmail dot com.