• We should now be fully online following an overnight outage. Apologies for any inconvenience, we do not expect there to be any further issues.

Did someone hack my Work Email?

olds

Elite Member
Mar 3, 2000
50,124
779
126
Edit
Since I got an answer I took out the real addresses so that csaddict wouldn't spam anyone. ;)
End Edit
This email came to me, from me. I didn't send it. My mother also got an email from me that I didn't send.
oldsmoboat@xxxxx.com is me, chris_smith@work.com is my work email, mybrother@xxxxx.com is my brother. I don't use Outlook at work.
Here is the header.

From:
chris_smith <chris_smith@work.com>

To :
oldsmoboat@xxxxx.com

Subject :
Darling

Date :
Tue, 07 May 2002 21:35:19 -0400

MIME-Version: 1.0
Received: from barry.mail.mindspring.net ([207.69.200.25]) by hotmail.com with Microsoft SMTPSVC(5.0.2195.4905); Tue, 7 May 2002 22:17:56 -0700
Received: from 216-224-150-178.thegrid.net ([216.224.150.178] helo=Lumzqlcc)by barry.mail.mindspring.net with smtp (Exim 3.33 #1)id 175GMQ-0007FF-00for oldsmoboat@xxxxx.com; Tue, 07 May 2002 21:35:19 -0400
Message-Id: <E175GMQ-0007FF-00@barry.mail.mindspring.net>
Return-Path: mybrother@xxxxxcom
X-OriginalArrivalTime: 08 May 2002 05:17:56.0666 (UTC) FILETIME=[B66EF9A0:01C1F64F]
View E-mail Message Source

 

thEnEuRoMancER

Golden Member
Oct 30, 2000
1,415
0
71
Your email was probably in address book of some person whose computer is infected with a variant of Klez worm - and the worm specified you as sender.


 

Hossenfeffer

Diamond Member
Jul 16, 2000
7,462
1
0
1-

<< This email came to me, from me. I didn't send it. My mother also got an email from me that I didn't send. >>

2-

<< Subject : Darling >>

3-

<< Received: from barry.mail.mindspring.net >>



Likely the Klez worm or possibly Gokar...

Have your brother do an anti-virus scan. Same boat for your mom and make sure the folks at work are up to snuff as well.
 

Descartes

Lifer
Oct 10, 1999
13,968
2
0
Keep in mind, that an email can quite easily be made to look as though it came from someone else. The only true means to identify the source is to look at the header. An example of how simple one can "spoof" the source of an email (spoofing the actual IP in the header is much, much more difficult, but possible)...

Telnet to port 25 of an smtp server that either relays, or that you have authoritative access to. Type in the following commands...

helo yourdomain.com
mail from:you@yourdomain.com
rcpt to:someoneelse@anotherdomain.com
data
From: You <you@yourdomain.com>
To: Someone Else <someoneelse@anotherdomain.com>
Subject: Test

Your data goes here

.

That's it. After the "data" segment, the From, To, and Subject lines are used primarily by email clients like Outlook. Anyway, the point is, don't always trust the source of an email by the name, or email address, alone :D
 

olds

Elite Member
Mar 3, 2000
50,124
779
126
I don't have the virus as I have already scanned for it. My brother very well may though. I'll tell him about it. Thanks for the info.