Dirty Spamming Ba$@*#@s

Posted by: lopan

Dirty Spamming Ba$@*#@s - 19/09/2002 06:28

So the last couple of days I've been receiving a enormous amount of email. At first I just tried to ignore it (this is a hotmail account) and delete it... then I noticed that the majority of them were return emails. Basically some spammer has targeted my email address and is using it to spam with (he's not actually using my account.... just attaching my name somehow)..... So basically everytime his little spam list encounters an invalid name, that server sends a return email to me creating enormous amounts of email in my box. My question is, is there anyway to stop this?
Posted by: fusto

Re: Dirty Spamming Ba$@*#@s - 19/09/2002 06:35

I had this same exact problem.
I read through the returned email headers, and discovered that the spammer was using an earthlink account.
I sent an email to [email protected] explaining the situation and I attached the emails with intact headers, so they could see for themselves.
I got an email back the same day, telling me they had tracked down his account and terminated him.
No problems since.
Look through the return email headers and see if you can track down the source.
Good luck!
Z~
Posted by: DeadFire

Re: Dirty Spamming Ba$@*#@s - 19/09/2002 07:11

Yes, I think fusto is right. This person likely just set up his return address in the email he is sending out to be your address. This way he won't have to waste time checking all the returned messages and deleting them, and can keep himself busy spamming people.
Posted by: lopan

Re: Dirty Spamming Ba$@*#@s - 19/09/2002 09:49

so... I've been going through all the returned mail.... mostly ip addresses that don't respond to an nslookup.... but this was in the header for one of them

Reporting-MTA: dns; mel-rti21.wanadoo.fr
Received-from-MTA: dns; compuserve.com (61.11.75.128)
Arrival-Date: Thu, 19 Sep 2002 14:49:32 +0200

Final-Recipient: rfc822; [email protected]
Action: Failed
Status: 5.1.1 (bad destination mailbox address)
Remote-MTA: dns; ms18-2.wanadoo.fr
Diagnostic-Code: smtp; 550 RCPT <[email protected]> ERROR. Mailbox
unavailable

So does this mean it's coming from compuserve? or is that just a hop point?

Posted by: tfabris

Re: Dirty Spamming Ba$@*#@s - 19/09/2002 10:05

Although you are right, it could be a spammer, there is another possibility that I wanted to make sure you knew about:

There is a chance that it's someone who is infected with an email virus and isn't deliberately trying to do anything bad. One of the characteristics of certain recent email viruses is to spoof the return address using a random name from the sender's address book (instead of using the sender's return address as older viruses did). I think they do this to make it more difficult to quickly identify and quarantine the infected machine.
Posted by: ashmoore

Re: Dirty Spamming Ba$@*#@s - 19/09/2002 10:27

That is correct,
most modern viruses like Klez will fake as much as it can in the header information so you cannot rely on anything in there, not even the routng info until you see your servers.
Remember that these things include thier own SMTP servers so they can fake anything.
Posted by: Tim

Re: Dirty Spamming Ba$@*#@s - 19/09/2002 19:07

That happened to me with my primary hotmail account a few years ago - it ended up getting removed. Pissed me off.
Posted by: lopan

Re: Dirty Spamming Ba$@*#@s - 22/09/2002 21:39

I actually sent a email to compuserve's spam abuse address... I didn't hear anything back from them. The day after though I recieved no return email notifications.... I thought they'd taken care of it. I looked todayhowever and had 2 in my inbox, this is still considerably less then what I was getting...
Posted by: davey_boy

Re: Dirty Spamming Ba$@*#@s - 25/09/2002 12:41

http://www.energis.com/abuse/

Here you can follow instructions on identifying the originator of email, enabling you to make a full report to the relevant ISP.

I had a different reason, someone was sending out abusive email disguised as thought they were from my email account.