Go Back   HostGator Peer Support Forums > HostGator Peer Support Forums > Shared Hosting Support

Notices

Reply
 
Thread Tools
  #1  
Old 01-27-2004, 07:27 PM
bonson bonson is offline
Hatchling Croc
 
Join Date: Dec 2003
Posts: 3
Default

I'm not sure exactly what is causing this, but I'm getting a LOT of emails bounced back to my primary email address with undeliverable emails. The email headers show they are originating from my domain, except they are not mail accounts I have set up. I only set up 3 mail accounts and the ones that are being bounced back are originating from generic names like John@, Jerry@, Smith@ (none of which are setup).

Most of the emails are attached with a small 22kb attachment that is zipped with odd file names.

I have scanned my system with an up-to-date scanner and never opened any of the attachments. I'm confident there is no virus on my system. None of my friends are getting these emails either.

Does anyone here have any input on what may be causing this?

Thanks in advance,
-Bonson Yee
www.bkphotog.com
Reply With Quote
  #2  
Old 01-27-2004, 07:35 PM
GatorBrent's Avatar
GatorBrent GatorBrent is offline
HostGator Staff
 
Join Date: Oct 2002
Location: houston, texas
Posts: 3,006
Default

Everyone everwhere is getting weird emails like this. Ignore them they aren't coming from your domain, nor are they coming from the server. It's spam an attempt to get you to open it / be infected. DO NOT OPEN THEM! NEVER OPEN ANY ATTACHMENT EVEN IF YOU ARE BEST FRIENDS WITH WHO IS SENDING

http://www.cnn.com/2004/TECH/interne...ead/index.html

It's a worm hitting windows boxes, and is one of he biggest to hit in a long time. 1 /12 emails on the internet right now are it according to the news.

Give it a week or two before it dies down.
__________________
Gators love marshmallows.
Reply With Quote
  #3  
Old 01-27-2004, 07:44 PM
bonson bonson is offline
Hatchling Croc
 
Join Date: Dec 2003
Posts: 3
Default

Whew - thanks for the quick response. Huge relief - I was worried i uploaded something infected today.
Reply With Quote
  #4  
Old 01-27-2004, 07:47 PM
angeleyz angeleyz is offline
Junior Croc
 
Join Date: Sep 2003
Location: Everywhere at once
Posts: 192
Default

I thought I'd been hacked. LOL I asked about this just after it was posted. Thanks Brent
Reply With Quote
  #5  
Old 01-27-2004, 07:50 PM
GatorBrent's Avatar
GatorBrent GatorBrent is offline
HostGator Staff
 
Join Date: Oct 2002
Location: houston, texas
Posts: 3,006
Default

Yeh I was little worried as well. I thought jessica downloaded a virus / worm and it infected our home network.
__________________
Gators love marshmallows.
Reply With Quote
  #6  
Old 09-14-2004, 11:07 AM
tjs tjs is offline
Hatchling Croc
 
Join Date: Jun 2004
Location: Oklahoma
Posts: 11
Default Re: Weird emailing - virus?

Something like this has been happening to me, only today I received an email from someone (they exist, I checked their site) claiming that I sent them the virus and I've been black listed on that site as well as a few others.

The folders sent to me are titled things like mydomain.txt or .zip(my domain name) and according to the raw source they were sent from my server. One of the ones I received today had the folder named myusername@mydomain.zip. and the raw source states that it was sent from my server by the username postmaster, which I never placed in my email manager.

I've checked all my cgi-bins and found nothing that I didn't put in them. Is it possible that my mail server is sending these things? I'm concerned about being black listed by search engines. The server that these are coming from according to the raw source is hummer.websitewelcome.com. If not, does anyone have any idea how the raw source traces it to our server?
__________________
WichitasGateway.com
the gateway to the Wichitas Gateway to the web
Reply With Quote
  #7  
Old 09-14-2004, 02:54 PM
GatorJustin's Avatar
GatorJustin GatorJustin is offline
Banned User
 
Join Date: Apr 2004
Location: Atlanta, GA
Posts: 771
Default Re: Weird emailing - virus?

tjs, just because your address appeared in the From: field, does not mean you actually sent the virus or are infected yourself. You are probably fine, and I would say that the owners of that site need to brush up a bit on their knowledge before blacklisting what is likely an innocent domain.

-Justin
Reply With Quote
  #8  
Old 09-14-2004, 11:11 PM
karz10 karz10 is offline
Junior Croc
 
Join Date: Aug 2004
Posts: 123
Default Re: Weird emailing - virus?

I've seen this happen before. Many times, I could create a link between where these things came from and how it was getting back to me. For example, I know some people that I've networked with in a business sense that have copied me on emails before and made the mistake of not BCCing everyone, so I knew some of the emails that he sent to. I also knew where he hosted.

So, when the emails started bouncing back to me, or in some cases someone complained to me, I went and looked to discover the email actually originated from the SMTP server of my associate's host, and was able to figure out that in some cases the emails originated from one of his company machines or from the machine of someone else in his circle of associates that also received those emails that I was copied on, so the virus of the infected machine went out sending the virus to emails the hacker wanted to send to, and it would claim to be from me and my domain, but I had nothing to do with it, and it was not traced to me in any way.

Eventually it blew over, and I think most anyone who really knows how these things work would not penalize you if it did not *really* come from you, which it likely did not. Let us know if you learn otherwise...

Karsten
Reply With Quote
  #9  
Old 09-15-2004, 06:23 AM
JZ JZ is offline
Swamp Croc
 
Join Date: Aug 2004
Location: Harrisburg, PA
Posts: 364
Default Re: Weird emailing - virus?

There is an anti-forgery solution available that is trying to curb the spoofing of domains. I have not looked in to it closely but here is the url if you would like to try it for yourself. http://spf.pobox.com/
Reply With Quote
  #10  
Old 09-22-2004, 04:04 PM
Thomas's Avatar
Thomas Thomas is offline
Junior Croc
 
Join Date: Jun 2004
Posts: 195
Default Re: Weird emailing - virus?

Hi all. Just felt I should share some experiences here.

I've been familiar with spoofing for a couple years. I had this one client out of several that was a victim, and I was getting 5 + "undeliverable" emails a day from him. Each had a virus attached. He wasn't sending them. I was convinced he had a virus on his machine, but he didn't (at least not anymore).

It's my understanding that certain viruses will collect all the email addresses on your system and use them as both senders and/or recipients (spoofing) to propagate themselves. Then each recipent that gets infected magnifies the problem, and so on..... So, long after you've cleaned your machine your email address is still out there being used as a "sender" address. Of course, spoofing can also be done manually and intentionally (I think).

It seemed there was nothing I could do about this. I was very concerned that for every "undeliverable" message, there were probably some actually getting through to people, and those people would complain, and my clients email would be banned by ISPs. But none of that happened. It eventually just stopped.

I developed a pretty ralaxed attitude about spoofing - ignore it and it will go away. Until last week.....

Apparently my brand new HostGator reseller domain was used to spoof some spam to someone. The recipient complained. The complaint made it to the datacenter, who complained to Hostgator, and HG was ON me like white on rice!

Now look, I've got this dinky little site that barely manages 50 hits on a good day. I hardly ever use my webmail - much less run a spamming operation. Besides, I'm trying to be a reseller. Why would I contaminate myself that way?

Never the less, I got a personal phone call from someone I'll call "higher up in the company" and I was treated to something just this side of an interrogation. I was left with a copy of the spam to dissect and use to defend myself - which I did successfully. I'm not complaining. I DO appreciate HGs strict spam policy. I'm GLAD they take it so seriously. But spoofing has got to be treated with the same conviction. It's NOT going away.

I breifly visited the site Justin mentioned. I found it very confusing but eventually I hope to utilize this tool. I hope everyone, including HG will take this problem more seriously.

That's all.
Reply With Quote
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
weird server setup brad98 Shared Hosting Support 2 07-10-2004 03:15 PM
[Closed] Please help with a weird problem. oats Shared Hosting Support 2 06-30-2004 02:21 AM

All times are GMT -5. The time now is 11:05 AM.