Originally posted by: Anonemous
🙁 i haven't gotten any email from myself...
Originally posted by: Joemonkey
Anyone have any idea what is going on? So far 10 or so people here have received an email with a 3 or 4 digit number in the subject and a 3-5 digit number in the body, and that's it. In looking at the logs it seems there is some sort of directory harvest attack going on, but I'd like to know how the "from" email is getting spoofed.
Originally posted by: DaiShan
Originally posted by: Joemonkey
Anyone have any idea what is going on? So far 10 or so people here have received an email with a 3 or 4 digit number in the subject and a 3-5 digit number in the body, and that's it. In looking at the logs it seems there is some sort of directory harvest attack going on, but I'd like to know how the "from" email is getting spoofed.
LOL please tell me you aren't the net admin...
Originally posted by: DaiShan
Originally posted by: Joemonkey
Anyone have any idea what is going on? So far 10 or so people here have received an email with a 3 or 4 digit number in the subject and a 3-5 digit number in the body, and that's it. In looking at the logs it seems there is some sort of directory harvest attack going on, but I'd like to know how the "from" email is getting spoofed.
LOL please tell me you aren't the net admin...
Hahaha, does that screw with the noobs sending internal mail to @yourdomain.com?Originally posted by: her209
On our mail filter server, I block all emails that say they are from my domain.
Originally posted by: Phoenix86
Hahaha, does that screw with the noobs sending internal mail to @yourdomain.com?Originally posted by: her209
On our mail filter server, I block all emails that say they are from my domain.
Originally posted by: Homerboy
Originally posted by: Phoenix86
Hahaha, does that screw with the noobs sending internal mail to @yourdomain.com?Originally posted by: her209
On our mail filter server, I block all emails that say they are from my domain.
not to mention any applications that notify the Admin via email if XYZ doesn't run or there was a error on ABC etc etc.
Originally posted by: LOFBenson
Originally posted by: Homerboy
Originally posted by: Phoenix86
Hahaha, does that screw with the noobs sending internal mail to @yourdomain.com?Originally posted by: her209
On our mail filter server, I block all emails that say they are from my domain.
not to mention any applications that notify the Admin via email if XYZ doesn't run or there was a error on ABC etc etc.
If you have the resources to run multiple email servers it is trivially easy to do what her209 has suggested. It's also a good idea. It won't stop a current employee from forging an email from the CEO but it will stop former employees and useless spam like this. Internal email goes to one server which allows incoming email at @yourdomain.com. Internet email goes to another that doesn't.
Originally posted by: RedCOMET
This happened twice to me in one day. The first time, my computer wasn't even on at home. And even if my computer was on, there is no way i could send it to myself using my Universtiy Email address unless i used the webmail.
Oh well. I looked at the headers, but I couldn't make anything out of them. All of our mail gets filtered by Post Ini.
Originally posted by: Homerboy
Originally posted by: DaiShan
Originally posted by: Joemonkey
Anyone have any idea what is going on? So far 10 or so people here have received an email with a 3 or 4 digit number in the subject and a 3-5 digit number in the body, and that's it. In looking at the logs it seems there is some sort of directory harvest attack going on, but I'd like to know how the "from" email is getting spoofed.
LOL please tell me you aren't the net admin...
that comnent makes no freaking sense. So DaiShan, lets say YOU were the Admin, exactly how would you use your crystal ball to stop such emails? Especially since several of the people posting here are fairly well respected Network Engineers, Admins etc... Please, tell us all.
Originally posted by: DaiShan
Originally posted by: Homerboy
Originally posted by: DaiShan
Originally posted by: Joemonkey
Anyone have any idea what is going on? So far 10 or so people here have received an email with a 3 or 4 digit number in the subject and a 3-5 digit number in the body, and that's it. In looking at the logs it seems there is some sort of directory harvest attack going on, but I'd like to know how the "from" email is getting spoofed.
LOL please tell me you aren't the net admin...
that comnent makes no freaking sense. So DaiShan, lets say YOU were the Admin, exactly how would you use your crystal ball to stop such emails? Especially since several of the people posting here are fairly well respected Network Engineers, Admins etc... Please, tell us all.
I AM a Sys admin, and I DO receive these emails, but I fail to understand why you guys are flipping your lids over a widely known and long standing problem with the protocol. This is not new, this is not some crazy vulernability. Just tell your users to ignore the messages, or use your spam rules to help block them. I really can't believe this thread has gone on for so long. Especially since I already answered this question in the Networking forum yesterday...
Originally posted by: Number1
Originally posted by: DaiShan
Originally posted by: Homerboy
Originally posted by: DaiShan
Originally posted by: Joemonkey
Anyone have any idea what is going on? So far 10 or so people here have received an email with a 3 or 4 digit number in the subject and a 3-5 digit number in the body, and that's it. In looking at the logs it seems there is some sort of directory harvest attack going on, but I'd like to know how the "from" email is getting spoofed.
LOL please tell me you aren't the net admin...
that comnent makes no freaking sense. So DaiShan, lets say YOU were the Admin, exactly how would you use your crystal ball to stop such emails? Especially since several of the people posting here are fairly well respected Network Engineers, Admins etc... Please, tell us all.
I AM a Sys admin, and I DO receive these emails, but I fail to understand why you guys are flipping your lids over a widely known and long standing problem with the protocol. This is not new, this is not some crazy vulernability. Just tell your users to ignore the messages, or use your spam rules to help block them. I really can't believe this thread has gone on for so long. Especially since I already answered this question in the Networking forum yesterday...
Would you care to post your answer in THIS tread and in english please. That would probably terminate this tread...:roll:
Originally posted by: DaiShan
Originally posted by: Number1
Originally posted by: DaiShan
Originally posted by: Homerboy
Originally posted by: DaiShan
Originally posted by: Joemonkey
Anyone have any idea what is going on? So far 10 or so people here have received an email with a 3 or 4 digit number in the subject and a 3-5 digit number in the body, and that's it. In looking at the logs it seems there is some sort of directory harvest attack going on, but I'd like to know how the "from" email is getting spoofed.
LOL please tell me you aren't the net admin...
that comnent makes no freaking sense. So DaiShan, lets say YOU were the Admin, exactly how would you use your crystal ball to stop such emails? Especially since several of the people posting here are fairly well respected Network Engineers, Admins etc... Please, tell us all.
I AM a Sys admin, and I DO receive these emails, but I fail to understand why you guys are flipping your lids over a widely known and long standing problem with the protocol. This is not new, this is not some crazy vulernability. Just tell your users to ignore the messages, or use your spam rules to help block them. I really can't believe this thread has gone on for so long. Especially since I already answered this question in the Networking forum yesterday...
Would you care to post your answer in THIS tread and in english please. That would probably terminate this tread...:roll:
Umm, have you bothered reading this thread at all? SMTP is an insecure protocol, you can forge the from field with ease, that is what is happening here. I can't give you specific steps for spam rules because I don't know which service your organization uses to block spam. Additionally, this thread is in the wrong forum, and I'm going out of my way to REPOST information that is readily available because you are too lazy to click on the Networking link. Finally, technical implementations will never keep up with org policy. If you don't want (or don't know how) to update your spam filters, then just TELL the people in your organization to delete the message. I certainly hope that was clear enough for you.
anybody know the name of the worm?
I'd still guess worm or possibly spammer fishing for e-mail addresses.
Originally posted by: DaiShan
Especially since I already answered this question in the Networking forum yesterday...