SPAM is a huge problem for every email user. It is estimated that worldwide about 97% of email is SPAM, and in the US about 90%! I will leave the subject of filtering out the bad without losing the good email for another time as it is a large subject in its own right. But, what if YOUR ACCOUNT is the apparent source of some of this email? The embarrassment of having this happen will be small in comparison with the feeling of being victimized. This is a mugging as serious as any street crime, but without the bruises and bodily injury they often come with.
Over the last couple of weeks the email accounts of 3 people I know have been compromised. Two people had AOL accounts and one had a Hotmail address. The biggest reasons that a web based email account like this becomes compromised is because of a weak password. A weak password is often Short – under 6 characters, or a common word that is subject to being broken by a dictionary attack.
How can you tell that your account has been compromised as opposed to your email address just being conveniently scapegoated as the sender of SPAM? Probably the single distinguishing characteristic is if these emails are going to people in your address book. If you are beginning to get calls from people in your address book or these emails have an alphabetic group of address book entries, then your account has been compromised. Other evidence is if the emails show up in your “sent” folder.
If your account has become compromised your should immediately change the password to a good one. If possible, you should use a different computer from your main one in case that computer has been compromised too. You should scan your main computer to verify that it is clean from viruses, spyware and malware.
For one of my clients I was able to demonstrate that it was his account that had been compromised and not his computer by analyzing the email header which traces the path of the message. The following is a sample of the SPAM that was issuing from the account:
Hi ********,
As an FYI here is the header from the single “I need your help” spam I received. To let you follow this here are the steps this particular message traveled along the way to me. My markers are to the right and look like 1*, etc.
Headers are accumulated from the bottom up. Each time the message is “handled” a new wrapper is added at the top.
1* The visible headers that we get to see. These are “comment” only and as you have learned easily forgeable. This case was slightly more clever than most by not putting the recipients in the To or CC fields, and sending them back to you.
2* Message originated at IP 41.205.174.131 and was given to Yahoo email. As I mentioned on the phone this IP is in Nigeria, and this particular message was not handled or processed through AOL at all. The only AOL reference here is your email address. The originating IP can also be forged but that is substantially harder to do.
3* Yahoo passed the message to my email handler, Dreamhost
4* My SPAM scoring of this message for later automatic disposition
5* The message was queued awaiting my pickup
Sorry that your email address was used in this way. Also, note that this is not a strong piece of evidence that your AOL account was compromised. Only, that your email address got into the hands of bad people. A heads up from many people in your address book is better evidence that the account was compromised.
Please let me know if I can help you further.
Best,
Jeff
X-Antivirus: AVG for E-mail
Return-Path: <**********@aol.com>
X-Original-To: ******@********.com 5*
Delivered-To: x10674009@ommail-mx4.g.dreamhost.com
Received: from dieharder.dreamhost.com (fltr-in2.mail.dreamhost.com [208.97.132.72])
by ommail-mx4.g.dreamhost.com (Postfix) with ESMTP id 02F3270826A
for <******@*****.com>; Tue, 8 Feb 2011 10:17:22 -0800 (PST)
Received: from localhost (localhost [127.0.0.1])
by dird.dreamhot.com (Postfix) with ESMTP id F1D7E17BC05F
for <******@******.com>; Tue, 8 Feb 2011 10:17:21 -0800 (PST)
X-DH-Virus-Scanned: Debian amavisd-new at doesboard.dreamhot.com 4*
X-Spam-Flag: NO
X-Spam-Score:
X-Spam-Level:
X-Spam-Status: No, score=x tagged_above=-999 required=3 WHITELISTED tests=[]autolearn=unavailable
Received: from wishonastar.dreamhot.com ([208.97.132.72])
by localhost (doesgoodard.dreamhost.com [208.97.132.157]) (amavisd-new, port 10024)
with ESMTP id jvcLqO+zN34u for <******@******.com>;
Tue, 8 Feb 2011 10:17:21 -0800 (PST)
Received: from web8052.mail.md.yahoo.com (web8052.mail.md.yahoo.com [209.191.72.55]) 3*
by doesgoodard.dreamhost.com (Postfix) with SMTP id BE87E94020
for <******@******.com>; Tue, 8 Feb 2011 10:17:14 -0800 (PST)
Received: (qmail 96197 invoked by uid 60001); 8 Feb 2011 18:17:21 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s1024; t=1297189041; bh=yJEPBujlm/1RP9i/5glH3McEpcDZxWEyDs4frU5skiM=; h=Message-ID:X-YMail-OSG:Received:X-RocketYMMF:X-Mailer:Date:From:Reply-To:Subject:To:MIME-Version:Content-Type; b=aD9tIzQT/f9IrnqYYS0rdplVvkSe8JdmxhNktRrRv+y+LeqcdqvZlloNkfleQ4E+5vcP5/IXYkBHfBfnTyRKlGR5vbLM1G/Y8MrhkMDSVNWSCSs+c0A7MKmLLtl0PEfUtZJoRSoPvkjaBP7BafaesksE0BiCZ31rhZ3xkb5Jg+Y=
Message-ID: <93435.69149.qm@web02.mal.mud.yahoo.com>
X-YMail-OSG: yQMeRGMVM1mdmgMjzLgNylvoye3i6_1_dg2gRJBgxcTkQfi
CLk1nFO06KLTb5Dy3wf5fnN7qlkAG3ToAv0ZwWO_jSutxuhYi251TWaKXDCf
a8tNrV_H2shRX3CLtIknM4pnKWuvwXl8aJ4FBcBCw4oRd6htQtXa4A1tdE1W
07F36NY_5fs65pZHMjpI_VhNDByDr3lTtt0YsoKhlEtY3v5SaKCOAz.uI45c
_ijNtBpqu8sTtsf8sQ__meWAdsHW6mcTykk0-
Received: from [41.205.174.131] by wb002.mal.mud.yahoo.com via HTTP; Tue, 08 Feb 2011 10:17:21 PST 2*
X-RocketYMMF: whies@s***obal.net
X-Mailer: YahooMailClassic/11.4.20 YahooMailWebService/0.8.108.291010
Date: Tue, 8 Feb 2011 10:17:21 -0800 (PST)
From: ******** ******@aol.com 1*
Reply-To: ******@aol.com
Subject: I need your help.
To: ******@aol.com
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary=”0-804695509-1297189041=:69149″
From: ********** [mailto:*******@aol.com]
Sent: Tuesday, February 08, 2011 1:17 PM
To: ******@aol.com
Subject: I need your help.
| How’s your day going? I hope things are going well. Please I need you to help me out with something. Can I get a loan from you urgently? I`ll reimburse you under a week, I promise. I need to solve some personal problems at hand which have been giving me worries. I’d also prefer if we discuss this through email as I’m presently in England for a friend’s funeral. I’m sorry if I didn’t inform you about it, but please try and understand. I had to leave in a hurry on-hearing that the date of her burial was re-scheduled & it seems I can’t access my credit card & bank here in London. I`ll let you know how much I need if you are willing to assist me.
Thanks,
****** |