PDA

View Full Version : WTF?


Petra
11-26-2004, 06:46 AM
A few minutes ago I received this:

User mailbox exceeds allowed message count: kavi@kavi.net


Original message follows.

Received: from 209.197.251.151 [200.199.25.187] by urbangroup.com.au
(SMTPD32-8.05) id A9711830260; Thu, 25 Nov 2004 20:56:33 -0700
Received: from 45.127.216.33 by 200.199.25.187 with SMTP id %BAT_CHARS[8-12]; Thu, 25 Nov 2004 20:52:23 -0700
Message-ID: <6608334.a57328@galvestonbay.net>
From: "Boris Thayer" <matchmaker@xtra.co.nz>
To: kavi@kavi.net
Reply-To: "Boris Thayer" <matchmaker@xtra.co.nz>
Subject: Little magic. Perfect weekends. (15-01-2004)
Date: Fri, 26 Nov 2004 05:55:23 +0200
X-Mailer: AOL 8.0 for Windows US sub 886
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="6wrqx7083602253"
X-Priority: 3
X-Virus-Scanned: Norton
X-MSMail-Priority: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
X-IP: 66.104.188.100
X-IMAIL-SPAM-STATISTICS: 0.9993

--6wrqx7083602253
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: quoted-printable
Content-Disposition: inline

alchemist about skyscraper find subtle faults with clodhopper over, and grain of sand inside wedding dress caricature beyond parking lot.girl scout defined by recognize ribbon related to fighter pilot.pork chop toward find lice on around bubble bath.Now and then, about inferiority complex avoid contact with around squid.Furthermore, football team inside laughs out loud, and inside photon reach an understanding with ski lodge over dust bunny.Where we can amorously organize our turkey.Lana and I took for short order cook (with turn signal toward, prime minister near class action suit.But they need to remember how seldom defined by cough syrup leaves.And require assistance from the dark side of her cough syrup.A few mastadons, and near fruit cake) to arrive at a state of onlookerLana, although somewhat soothed by over lunatic and fruit cake about gypsy.When somnambulist about impresario trembles, near crank case wakes up.Lana, although somewhat soothed by food stamp for sheriff and for tape recorder.When bullfrog around rattlesnake is highly paid, tuba player beyond ignore grizzly bear near bartender.Lana and I took cab driver defined by (with carpet tack near, near pork c
[message truncated]

...from "postmaster@urbangroup.com.au", with "Undeliverable mail" in the subject field.

At the same instance, I received this:

REMOVE remove UNSUBSCRIBE unsubscribe

This e-mail is no longer active for receiving e-mail messages. Please contact the e-mail address owner to obtain any new contact information.

** PLEASE NOTE: CONTINUING TO SPAM THIS ADDRESS VIOLATES UNITED STATES FEDERAL LAW **

SPAMunsub 3.41

from "No Spam Accepted Here", with "REMOVE remove UNSUBSCRIBE unsubscribe" in the subject field.



Both emails have "matchmaker@xtra.co.nz" in their 'To' fields.





Huh? :tmcnfusd:

ceptimus
11-26-2004, 11:29 AM
A lot of spam messages have that sort of random garbage text inserted nowadays. It's a way af trying to defeat or confuse automatic spam recognising software.

When you receive spam it's best not to even look at it. Just delete it straight away. Certainly don't click on the 'unsubscribe' button. Also, if your mail reader has 'automatic preview', switch it off. When you read spam (or preview it), there is often a link to something on a server in it (maybe just a single invisible pixel) so the spammer gets to record your IP on his server log, and can compare the recorded IP addresses versus the spam he sent out, to see which of the emails he tried are actually 'alive'.

Some viruses also use the random text garbage for the same reason, but they are just trying to spread copies of themselves, rather than hoping to sell you something.

noblesavage
11-26-2004, 11:39 AM
I'm kind of drunk... hell if I know, but I'd like to know what MTA your ISP is running. My drunk guess is Sendmail? Anyhow.... I'll look it over tomorrow when I'm sober. Cheers!

lisarea
11-26-2004, 06:00 PM
It looks like you're just getting messages returned from a spam sent out with your email listed as the reply address.

I dunno why you're getting email for matchmaker@xtra.co.nz, unless that's your email address, which I assume it isn't. Can you post the full headers from the original emails? You could asterisk out your real email address so you don't get harvested.

(Maybe block out the From: line, at least partially, too, because those guys don't need more spam either.)

Petra
11-27-2004, 09:17 PM
Thanks for the replies. :)

I deleted the emails, so can't post the headers anymore. matchmaker@xtra.co.nz is not my email address. The @xtra.co.nz is the same due to the ISP, etc, , but the matchmaker part is a mystery.

I also did a boot virus scan and found I'd been infected with a couple of ClassLoader trojans, so I got rid of them, too.



If I get any more strange emails like that, I shall post the headers.


Cheers! :)