1. Welcome to Tacoma World!

    You are currently viewing as a guest! To get full-access, you need to register for a FREE account.

    As a registered member, you’ll be able to:
    • Participate in all Tacoma discussion topics
    • Communicate privately with other Tacoma owners from around the world
    • Post your own photos in our Members Gallery
    • Access all special features of the site

Spoofed spam emails

Discussion in 'Technology' started by MyToyTaco, Nov 12, 2014.

  1. Nov 12, 2014 at 9:43 AM
    #1
    MyToyTaco

    MyToyTaco [OP] ╒╪╕

    Joined:
    Sep 23, 2008
    Member:
    #9417
    Messages:
    4,385
    Gender:
    Male
    First Name:
    Nick
    wenatchee, wa
    Vehicle:
    09 DCLB 4x4
    I've been trying to figure this out, I can't seem to come up with an answer on my own.

    How is it that whoever is behind the spoofed spam gets the contact list for that email? My best guess is that the account was compromised at some point in the past and the contact list was saved.

    An interesting observation is that just about all of these targets use yahoo.

    I also get a kick out of seeing all of the different people/companies that my friends are emailing....:laughing:


    Thoughts??
     
  2. Nov 12, 2014 at 9:47 AM
    #2
    Aw9d

    Aw9d That one guy

    Joined:
    Nov 7, 2011
    Member:
    #66635
    Messages:
    19,236
    Gender:
    Male
    I have a buddy who's GF's job is to find email address and send out those annoying spam messages. She spends lots of time trying to find ways around the filters and what not.

    Your email address is distributed all over the internet regardless if you want it to be or not. Its not hard to find peoples email address these days.

    Best thing to do, is have 2 emails. One for friends/family/important stuff. Then another for junk/porn/shopping/etc that can be leaked out. Once it gets bad, delete it and create a new BS email account.
     
  3. Nov 12, 2014 at 9:49 AM
    #3
    frizzman

    frizzman Well-Known Member

    Joined:
    Sep 25, 2013
    Member:
    #113212
    Messages:
    5,321
    Gender:
    Male
    Pittsburgh, PA
    Vehicle:
    04 XCab 4x4 TRD/OR
    OME 2.5,Tundra 17s,Falken Wildpeak AT3W hitch w/ 7-pin, ARE cap, JVC HU w/BT, HID/LED lights
    x2

    defeating filters is easier with html. space out the letters in your words and the filters don't recognize them due to spaces. but html will combine them back due to eliminating spaces.
     
  4. Nov 12, 2014 at 9:52 AM
    #4
    MyToyTaco

    MyToyTaco [OP] ╒╪╕

    Joined:
    Sep 23, 2008
    Member:
    #9417
    Messages:
    4,385
    Gender:
    Male
    First Name:
    Nick
    wenatchee, wa
    Vehicle:
    09 DCLB 4x4
    Getting an email address and spoofing it is easy... the question is, how does the spoofer get the contact list for that email address?

    Is the only logical explanation that the account (or pc) was compromised at some point in the past thus exposing the contact list? Or is there some other way this is happening?
     
  5. Nov 12, 2014 at 9:59 AM
    #5
    MyToyTaco

    MyToyTaco [OP] ╒╪╕

    Joined:
    Sep 23, 2008
    Member:
    #9417
    Messages:
    4,385
    Gender:
    Male
    First Name:
    Nick
    wenatchee, wa
    Vehicle:
    09 DCLB 4x4
    :p I saw your post. your thoughts equal mine I just wanted to have an open discussion to see there are maybe other ways this is happening.

    I got a spoofed spam email from my wife and I maintain her PC. Her account or PC has never been compromised as far as I can tell. that's why I'm poking around for more info.

    Also any comments on why this is primarily happening to yahoo users?
     
  6. Nov 12, 2014 at 10:29 AM
    #6
    MyToyTaco

    MyToyTaco [OP] ╒╪╕

    Joined:
    Sep 23, 2008
    Member:
    #9417
    Messages:
    4,385
    Gender:
    Male
    First Name:
    Nick
    wenatchee, wa
    Vehicle:
    09 DCLB 4x4
    The interwebz is a tricky place these days, that's for sure! Always gotta be on your toes.
     
  7. Nov 12, 2014 at 12:15 PM
    #7
    Evil Monkey

    Evil Monkey There's an evil monkey in my truck

    Joined:
    Aug 8, 2007
    Member:
    #2352
    Messages:
    8,262
    Gender:
    Male
    First Name:
    Robert
    Escondido, CA
    Vehicle:
    07 4x4 DC SR5 TRD Off-road
    Weathertech front & rear mats, rear suspension TSB, Toytec AAL for TSB, Hi-Lift Jack, Bilstein 5100 & Toytec Adjustable coilovers, Built Right UCAs, KMC XD 795 Hoss Wheels, Definity Dakota MTs 285/75R16, Leer XR, Thule Tracker II & Thule MOAB basket
    If they're sending emails to her contact list then the account has been hacked. As to why it would happen to yahoo users, it's a big target. If you think the emails are actually coming from her account, I would change the password on the account to something complex.
     
  8. Nov 13, 2014 at 5:41 AM
    #8
    frizzman

    frizzman Well-Known Member

    Joined:
    Sep 25, 2013
    Member:
    #113212
    Messages:
    5,321
    Gender:
    Male
    Pittsburgh, PA
    Vehicle:
    04 XCab 4x4 TRD/OR
    OME 2.5,Tundra 17s,Falken Wildpeak AT3W hitch w/ 7-pin, ARE cap, JVC HU w/BT, HID/LED lights
    if you scan the hidden headers of an email you can grab all the addresses that it was sent to. even bcc field shows up.

    if any account was compromised that had her as a contact then it will send. before we switched out mail systems we had a few click on bad links or open messages and get their send-mail accounts taken over. they change the "reply to", "sent from" and any other field that would get a response from someone unaware
     
  9. Nov 13, 2014 at 6:08 AM
    #9
    Large

    Large Red

    Joined:
    Sep 10, 2011
    Member:
    #63268
    Messages:
    22,455
    Gender:
    Male
    Basically, when you enter your email address on any site it gets stored in to a huge list, and sold to the highest bidder. That's how they obtain your email address in the first place.
     
  10. Nov 13, 2014 at 6:14 AM
    #10
    TacomaRobert

    TacomaRobert Well-Known Member

    Joined:
    Jan 27, 2014
    Member:
    #121602
    Messages:
    254
    Gender:
    Male
    Couple of things.

    First spammers get emails easily. Sometimes just guess at them. Any reasonable guess is probably an email, true? They write computer programs that send emails to random made up addresses. When you "opt out" that doesn't really work, but it does tell them your email address is actively being used. Not only will they spam you, but will sell your address to others. And so on.

    Second, ideas like using two emails, one for friends, doesn't work. It used to fifteen years ago. But that myth persists. It will delay them for a while. But once it's ever found then it's over. If not for the above scenario, there are dozens and dozens more including your friends screwing up and letting it out for you.

    Finally, so what to do? There is only one good answer. Use a sophisticated server hosted email spam filter. Mcafee makes a fantastic one if you host your own email. Or gmail email is fantastic if you don't. They won't filter out good emails like some other bad services out there. You won't have to waste your life messing with settings since they are reputation based. Then watch your spam go to zero.

    Enjoy your email and don't waste your life managing it. Use my answer, and you're good to go.
     
    Last edited: Nov 13, 2014
  11. Nov 13, 2014 at 6:15 AM
    #11
    Large

    Large Red

    Joined:
    Sep 10, 2011
    Member:
    #63268
    Messages:
    22,455
    Gender:
    Male
    Just to clarify, not every website does this but a lot of them do.
     
  12. Nov 13, 2014 at 6:22 AM
    #12
    Nickel

    Nickel Well-Known Member

    Joined:
    Nov 22, 2012
    Member:
    #91659
    Messages:
    1,345
    Gender:
    Male
    First Name:
    Diego
    Rio Rancho New Mexico
    Vehicle:
    2013 T/X TRD
    does turning tires to black wall out count? How bout added snug top rebel.
    It's always an aol account that gets compromised in my experience. at least 5 acquaintances in the past year have had thier aol accounts hacked and spammed out messages to all contacts. At least it's blatantly obvious that it's been hacked.
     
  13. Nov 13, 2014 at 8:47 AM
    #13
    MyToyTaco

    MyToyTaco [OP] ╒╪╕

    Joined:
    Sep 23, 2008
    Member:
    #9417
    Messages:
    4,385
    Gender:
    Male
    First Name:
    Nick
    wenatchee, wa
    Vehicle:
    09 DCLB 4x4
    Interesting. So, If I were to send out a newsletter BCC'd to 50 people, and one of them has an infected PC, the controller of that malware can now mimic my email to those 50 people with their own special link included?


    I agree. I can also attest to the gmail spam filter. It friggin rocks. It pretty much catches all spam and rarely non-spam.
     
  14. Nov 13, 2014 at 8:42 PM
    #14
    TacomaRobert

    TacomaRobert Well-Known Member

    Joined:
    Jan 27, 2014
    Member:
    #121602
    Messages:
    254
    Gender:
    Male
    Thank you!

    Totally with you. There is nothing better than using the service of a large room full of talented intelligent people who work on this stuff 70 hours a week.

    Yes! Sign up for one Gmail address. Or, use mcafee for server based. Use it for whatever. Forget the nonsense. Enjoy your email again. Less aggravation. Get more time back in your life.
     

Products Discussed in

To Top