Need some help tracking Emails, etc

Collapse
This topic is closed.
X
X
 
  • Time
  • Show
Clear All
new posts
  • gmack5
    Veteran Member
    • Dec 2002
    • 1972
    • Quapaw, Oklahoma, USA.
    • Ryobi BT3000SX & BT3100

    #1

    Need some help tracking Emails, etc

    Someone has broken into my computer from another remote computer (I have a Yahoo Email account) and sent some rather offensive Emails over my signature and I need to know if it's possible to determine where they came from. Isn't the Originating Computer identified in an Eamil? Help me, please.
    Last edited by gmack5; 03-11-2007, 09:51 PM.
    Stop thinking why you can't and Start thinking how you CAN!
    Remember, SUCCESS comes in CANS!
    George
  • linear
    Senior Member
    • May 2004
    • 612
    • DeSoto, KS, USA.
    • Ryobi BT3100

    #2
    The problem (one of several) with email is that it's trivial to forge. Even without breaking into your computer, it's possible to send mail that appears to issue from you. In fact, breaking into your computer doesn't really add much in the way of effectiveness to the forgery. So that may or may not have happened.

    If you look at the headers in an email (which your mail program works hard to hide these from you) you'll see a "Received:" header for every mail server that handled your message on its way to the recipient. The line indicating who submitted it is often entirely absent (it's not mandatory unlike the server headers). So finding the point of origin is a challenge, especially when a forger would go to some lengths to obscure it.

    It gets worse--the only way to really assess the legitimacy of a sender is if you have a known good message with headers from their usual server. So ultimately there's no way to authenticate or identify a sender in any meaningful sense. There are optional add-on protocols for mail when this is important, but email is just trivial to forge.

    For what it's worth, a spammer used my valid address as a forged return address once to issue tens of thousands of reprehensible messages. Just the thousands of bounce messages (from bad recipient addresses, some fraction of the overall payload) that came back were a huge overload on my end. Essentialy, I am powerless to stop it (as are most people that do not operate mail servers themselves). The mail protocols are broken.

    I ran mail servers for a living for several years before the problem was this bad.
    Last edited by linear; 03-11-2007, 10:25 PM. Reason: added some crud
    --Rob

    sigpic

    Comment

    • Kristofor
      Veteran Member
      • Jul 2004
      • 1331
      • Twin Cities, MN
      • Jet JTAS10 Cabinet Saw

      #3
      I agree with linear.

      <5% chance that someone broke into your account. In that case it's 99% that you know the person doing it, and it's probably easier to work from the other direction knowing which PCs they use and investigating forward not backward.

      >95% chance that nobody broke into your account. Many viruses will look through an infected PC's inbox/outbox/addressbook and then send messages that appear to be from the addresses contained therein.

      For spam messages as Linear mentioned it's trivial to fake the origin info. Relatively little you can do about that other than avoiding putting your email address in widely read locations, and (sometimes harder) picking an address that's less likely to be selected at random (ie not first initial, last name).

      Comment

      • LCHIEN
        Super Moderator
        • Dec 2002
        • 22072
        • Katy, TX, USA.
        • BT3000 vintage 1999

        #4
        rob -linear (incidentally I like the new list of ingredients, Rob)
        has given you a great summary, I started to do so but was a little over my head. I myself had my email address hijacked and used in this way where they issues what must of been 10s of thousands of spam mails and all I ever saw were the few hundred which bounced each day due to old, discontinued addresses to those rejected by spam filters. This went on for two- or three weeks then stopped. Ugh! My computer was never compromised but they got hold of my e-mail address to use as a legitimate sounding address to use for a sender in their spams.

        That's one of the problems with e-mails, easy to forge, no way to authenticate. The original e-mail protocol was probably back from the DARPAnet days when only scientists had access to large networked computers and was just a informal way of exchanging notes. Security and authenticity and traceability were not in the plans.
        Last edited by LCHIEN; 03-12-2007, 08:02 AM.
        Loring in Katy, TX USA
        If your only tool is a hammer, you tend to treat all problems as if they were nails.
        BT3 FAQ - https://www.sawdustzone.org/forum/di...sked-questions

        Comment

        Working...