gilprice.com

New Tricks with SPAM

By: Gil Price
Original: 5/21/2003
Modified: 11/8/2005

Anyone an expert on SPAMmers and their tools and techniques? I'm looking to educate myself. I've been getting a lot of e-mail bounces returned to me lately from AOL for e-mail I didn't send! Seems Spammers have a new method of sending their garbage. They put someone elses e-mail address in the From: and Reply To: fields, then send the SPAM to a third party with 3 CC: addresses.

So what happens is I get the bounces for any address that is no longer valid. The SPAM in this particular instance has the following headers:

Received: from rly-yb04.mx.aol.com (rly-yb04.mail.aol.com [172.18.146.4]) by str-m03.mail.aol.com (v92.16) with ESMTP id RELAYIN8-93ec42b532a9; Thu, 15 May 2003 20:05:39 -0400 Received: from sc.rr.com ([61.171.56.88]) by rly-yb04.mx.aol.com (v93.12) with ESMTP id MAILRELAYINYB410-19a3ec42b391df; Thu, 15 May 2003 20:05:19 -0400 Received: from relay.2yahoo.com ([138.44.247.90]) by smtp-server1.cfdenselr.com with SMTP; Thu, 15 May 2003 15:07:25 +1200

As you can see, the mail originates at :smtp-server1.cfdenselr.com, this is a non-existant domain, and is relayed through relay.2yahoo.com. While I am in no danger of having my mail server blacklisted, I am concerned with my e-mail address be used as the sender and reply-to addresses. This can lead to confusion as most people would not know to look at the e-mail message headers, let alone what a header is. Once I finish putting together a SPAM disclaimer, I'll post it here for all to see, also in my fight to combat SPAM, I'm going to have to add TMDA to my arsenal. For a short article on modern con men, I found this one to be enlightening: http://members.aol.com/phillylawyer13/conmen.pdf

Return Home

The views expressed within this site pretty much represent those of the author, except where otherwise attributed.

Copyright (c) 2000-2011 Gil Price. All rights reserved. I can be reached for comments at gprice[at]gilprice.com, please use [Comment] in the subject link and do include the square brackets.