Jump to content

Scanning Evaded?


Recommended Posts

I've been getting flooded with these messages, same subject each time, several times a day, directly to my SpamCop account addressed from cesmail. My account name is pretty short, so I'm guessing it was discovered via some kind of brute force attack. What's unusual is that the X-spam-* tags are absent from these messages. I routinely check my machine for spyware and virii, and these persist even after I changed my forwarding address.

I've created a client filter that deletes everything that isn't scanned, but how or why would a message sent to my SpamCop account not have these tags?

Here's a sample:

Wazoo replaced full text header with a Tracking URL of http://www.spamcop.net/sc?id=z744217735z2d...b136ad88d96e64z

Link to comment
Share on other sites

I've been getting flooded with these messages, same subject each time, several times a day, directly to my SpamCop account addressed from cesmail.

I'm not quite following what you said ... My guess is that you have stuff being forwarded from your SpamCop account to another account. but ..??? I think more detail on how and what you have set up on your SpamCop account might be in order.

My account name is pretty short, so I'm guessing it was discovered via some kind of brute force attack.  What's unusual is that the X-spam-* tags are absent from these messages.  I routinely check my machine for spyware and virii, and these persist even after I changed my forwarding address.

I don't quite see the logic involved in this either. I thought you were talking about "incoming" e-mail...????

I've created a client filter that deletes everything that isn't scanned, but how or why would a message sent to my SpamCop account not have these tags?

Easy assumption is how your e-mail is actually handled, but ...??? see above perhaps?

Link to comment
Share on other sites

I'm not quite following what you said ... My guess is that you have stuff being forwarded from your SpamCop account to another account. but ..??? I think more detail on how and what you have set up on your SpamCop account might be in order. 

I don't quite see the logic involved in this either.  I thought you were talking about "incoming" e-mail...????

Easy assumption is how your e-mail is actually handled, but ...??? see above perhaps?

25791[/snapback]

Let me clarify by saying that I don't actually distribute my spamcop address. I have a series of aliases that point to the spamcop address, which itself points to a single "trusted" address. I've been doing this for so long that I've taken my practice for granted.

As for spyware and virii prevention, I mention these as it would be plausible for these messages to have originated from my own machine by some malicious program if I were more lax about my PC's security.

All said, I've forwarded a few of the messages to support for review.

Link to comment
Share on other sites

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...