Hello and welcome to CertForums.co.uk, here we host free active certification forums with links to the best free resources for Microsoft's MCSA MCSE MCDBA Cisco's CCNA CCDA and CCNP, and CompTIA's A+ Network+ i-NET+ and Security+ certifications in the UK. If you wish to post or use other advanced features you will need to register first. Registration is absolutely free and takes only a few minutes to complete so sign up today!

If you have any problems with the registration process or your account login, please contact support

Go Back   CertForums > Computing Support Forums > Security & Viruses
Home Forums Register Search Today's Posts Mark Forums Read

Security Issue?

Post New ThreadReply
 
Thread Tools Display Modes
  #1  
Old 26-Mar-2008, 09:27 AM
nXPLOSi nXPLOSi is offline
Lifetime Member
Posts: 1,952
Points: 469 nXPLOSi has over 250 pointsnXPLOSi has over 250 pointsnXPLOSi has over 250 pointsnXPLOSi has over 250 pointsnXPLOSi has over 250 points
Power: 27
None
Join Date: 25 Sep 2006
Location: London
Age: 22
Certifications: A+, Network+
WIP: 70-270
Security Issue?

Hi Guys,

Need a little help with an issue I *think* we're having. Im getting alot of returned emails, an example below..

Your message did not reach some or all of the intended recipients.

Subject: Naked Shakira Clip
Sent: 26/03/2008 07:23

The following recipient(s) could not be reached:

charles@whatcomsoccer.com on 26/03/2008 10:12
The e-mail account does not exist at the organization this message was sent to. Check the e-mail address, or contact the recipient directly to find out the correct address.
< mx1.hardlines.com #5.1.1 SMTP; 550 5.1.1 User unknown>


Im wondering if somehow these are being sent from us? Perhaps a virus of some sort? I really have no experience in this area!!

Cheers

 
Reply With Quote
  #2  
Old 26-Mar-2008, 09:29 AM
Fergal1982's Avatar
Fergal1982 Fergal1982 is offline CertForums News Posting Member
Linux Àihǎozhě: bù zàihū!
Posts: 2,858
Points: 4243 Fergal1982 has over 4000 pointsFergal1982 has over 4000 pointsFergal1982 has over 4000 pointsFergal1982 has over 4000 pointsFergal1982 has over 4000 pointsFergal1982 has over 4000 pointsFergal1982 has over 4000 pointsFergal1982 has over 4000 pointsFergal1982 has over 4000 pointsFergal1982 has over 4000 pointsFergal1982 has over 4000 points
Power: 78
None
Join Date: 04 May 2004
Location: Aberdeen, UK
Age: 25
Certifications: ITIL Foundation
WIP: 70-536,70-294,(A+), Procastination+
most likely someone spoofing your address mate. nothing you can really do about it.


"Im Nerdy in the extreme and whiter than sour cream"


ObsidianPhoenix - my development blog



 
Reply With Quote
  #3  
Old 26-Mar-2008, 10:36 AM
Tinus1959's Avatar
Tinus1959 Tinus1959 is offline
Lifetime Member
Posts: 1,355
Points: 1093 Tinus1959 has over 1000 pointsTinus1959 has over 1000 pointsTinus1959 has over 1000 pointsTinus1959 has over 1000 pointsTinus1959 has over 1000 pointsTinus1959 has over 1000 pointsTinus1959 has over 1000 pointsTinus1959 has over 1000 points
Power: 26
None
Join Date: 11 Apr 2007
Location: The Netherlands
Age: 48
Certifications: See my signature
WIP: MCSD, MCAD, CCNA, CCNP
Looks like a worm to me.


MCP (NT 3.51) MCSE (NT 4.0, 2000, 2003) MCSA (2000, 2003), MCT (since 1999), Vista, Exchange 2007, MCTS server 2008 (3x), A+, Network+, Security+, CEH.
 
Reply With Quote
  #4  
Old 26-Mar-2008, 12:51 PM
hbroomhall hbroomhall is offline
Premium Member
Posts: 6,043
Points: 2032 hbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 points
Power: 86
None
Join Date: 08 Sep 2005
Location: Tunbridge Wells, Kent
Certifications: ECDL A+ Network+ i-Net+
WIP: Server+
Fergal is spot on. It is almost certainly someone spoofing your address. Quite common - I've been seeing this for some years.

A closer look at the headers should make this obvious.

There is very little that can be done about it.

Harry.

 
Reply With Quote
  #5  
Old 26-Mar-2008, 03:05 PM
BosonMichael's Avatar
BosonMichael BosonMichael is offline
Premium Member
Posts: 10,163
Points: 4789 BosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 points
Power: 152
None
Join Date: 02 Nov 2006
Location: near Nashville, TN
Age: 38
Certifications: MCSE+I, MCSE: Securi.. huh? out of room?
WIP: Just about everything!
Quote:
Originally Posted by nXPLOSi View Post
Subject: Naked Shakira Clip
...
I really have no experience in this area!!
Mmmm-hmmm... that's what they ALL say when they're caught! heehee!


BosonMichael
MCSE+I, MCSE: Security, MCDST, MCDBA, OCP, CCNP, CCDP, CNE, SCSA, Security+, Linux+, Server+, Network+, A+
Served proudly, US Army, 98C Intelligence Analyst, '89-'92
 
Reply With Quote
  #6  
Old 26-Mar-2008, 03:15 PM
nXPLOSi nXPLOSi is offline
Lifetime Member
Posts: 1,952
Points: 469 nXPLOSi has over 250 pointsnXPLOSi has over 250 pointsnXPLOSi has over 250 pointsnXPLOSi has over 250 pointsnXPLOSi has over 250 points
Power: 27
None
Join Date: 25 Sep 2006
Location: London
Age: 22
Certifications: A+, Network+
WIP: 70-270
Lol BM, it wasn't me, honest boss !!

Thanks for the replies guys, most helpful. It is a pain as its increased the amount of crap we're getting quite abit in the last few days, but nevermind, if it cant be helped it cant be helped.

Thanks again !

 
Reply With Quote
  #7  
Old 26-Mar-2008, 06:11 PM
hbroomhall hbroomhall is offline
Premium Member
Posts: 6,043
Points: 2032 hbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 points
Power: 86
None
Join Date: 08 Sep 2005
Location: Tunbridge Wells, Kent
Certifications: ECDL A+ Network+ i-Net+
WIP: Server+
You will find that this happens in batches. After a few days the bounces will die down as the spammer will someone else's address.

Harry.

 
Reply With Quote
  #8  
Old 27-Mar-2008, 01:41 PM
sunn sunn is offline
Lifetime Member
Posts: 1,139
Points: 1057 sunn has over 1000 pointssunn has over 1000 pointssunn has over 1000 pointssunn has over 1000 pointssunn has over 1000 pointssunn has over 1000 pointssunn has over 1000 pointssunn has over 1000 points
Power: 22
None
Join Date: 15 Jan 2008
Location: Canada
A suggestion is to ‘remind’ your users of this type of spam tactic and make sure they don’t open any emails and/or attachments they don’t recognize. Reference a specific clause in the employee handbook or other organizational document if possible.

Sounds simple, but it’s amazing how many folks will open an attachment in an email that looks to have bounced back, but they never sent in the first place.


____
Sunn
 
Reply With Quote
Post New ThreadReply Spread this thread: Submit this thread to digg Submit this thread to del.icio.us


Go Back   CertForums > Computing Support Forums > Security & Viruses


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Great Apache security book ffreeloader The Lounge - Off Topic 3 13-Mar-2008 03:37 PM
Security Power Tools tripwire45 Reviews 1 03-Mar-2008 11:19 PM
Network Security Assessment, 2nd Edition tripwire45 Reviews 2 21-Dec-2007 06:06 PM
Starting a Career in Cyber Security tripwire45 News 1 08-Nov-2007 04:26 PM


All times are GMT. The time now is 12:20 AM.

Powered by vBulletin® Version 3.6.10
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
CertForums.co.uk (C) copyright 2003-2007 All Rights Reserved. Content published on CertForums.co.uk requires permission for reprint.
Hosted by Lunarpages