Mexico Connect
Forums > Specific Focus > Technical Mexico
 


Uncle Donnie

Apr 21, 2004, 11:50 AM

Post #1 of 15 (1032 views)

Shortcut

Website attack

Can't Post |
Hi Folks,

Big personal problem I hope someone can help with.

Facts: My website is handled through earthlink. I'm under a major spam attack.

The messages come in but once deleted they re-date and re-send. In other words, I get the same messages over and over, just with new dates. In addition some of them repeat so that I get from 2 to 10 copies of the same mail in each batch.

Does anyone have a suggestion as to a program or anything else I can do to stop this?

Example: 10:55 last night after I cleared my mailbox I had 9 legitimate messages left.

This morning at 10:16 when I logged on I had 1711 new spam messages. I cleared them all by 11:07.

At 12:49 I had 678 new spam messages. I emptied them by 1:16.

Some are coming from my MC mailbox and some are masquerading as mail from MC and some are masquerading as mail from my own site.

And it's interesting that it's spam of a different nature than that I receive on my Yahoo account (very little there--maybe 10-12 a day).

Thanks,
UD

Shameless self-promotion:
http://www.headformexico.com



Uncle Jack


Apr 21, 2004, 1:34 PM

Post #2 of 15 (1018 views)

Shortcut

Re: [Uncle Donnie] Website attack

Can't Post | Private Reply
Somebody up there likes you, Donnie!

uj


Uncle Donnie

Apr 21, 2004, 4:10 PM

Post #3 of 15 (1008 views)

Shortcut

Re: [Uncle Jack] Website attack

Can't Post |
And regarding the ones I've already contacted: Have you ever noticed how quiet these techies get and how anxious they are to change the subject when faced with a challenge more complicated than rudimentary installations or parts peddlin'?

Pete, remember your recent column where you indirectly poked fun at those of us who are less technically proficient by writing that your local computer demi-gods couldn't figure out why we paid them to set up our computers?

I can't figure out why they're not flooding this forum with solutions and suggestions. Naked emperors I guess.

Obviously I'm in a pretty foul mood right now.

Shameless self-promotion:
http://www.headformexico.com


Marlene


Apr 21, 2004, 4:17 PM

Post #4 of 15 (1006 views)

Shortcut

Re: [Uncle Donnie] Website attack

Can't Post | Private Reply
Hi UD,
I sent you a very sympathetic message (via this forum) and it seems to have been eaten by cyber gremlins. Shall we trust my memory to repost what I said? Wait, I have to watch the Dawn Princess sail from the port first. I will send you a picture to cheer you up!
Warm regards,
Marlene.


Uncle Donnie

Apr 21, 2004, 4:48 PM

Post #5 of 15 (1003 views)

Shortcut

Re: [Marlene] Website attack

Can't Post |
That's just one of the resons I love you Marlene! Thanks.

Wish I could be there with you and Santana, sittin' high on a hill or down in La Puntilla eatin' fresh Mazatlan fish and sippin' cold Pacificos.

Shameless self-promotion:
http://www.headformexico.com


johanson / Moderator


Apr 21, 2004, 5:24 PM

Post #6 of 15 (999 views)

Shortcut

Re: [Uncle Donnie] Website attack

Can't Post | Private Reply
I wish I were smart enough to help you Uncle Donnie. When you phoned the office this morning and mentioned the problem, I really felt bad, but sadly that area is not one of my areas of expertise.

They did let me return the used coffee cups today to the CIA coffee shop, though, so I must be gaining some acceptance at the local ISP.


(This post was edited by johanson on Apr 21, 2004, 8:20 PM)


Marlene


Apr 21, 2004, 6:30 PM

Post #7 of 15 (995 views)

Shortcut

Re: [Uncle Donnie] Website attack

Can't Post | Private Reply
As promised, to distract UD from his annoying Spam-a-rama problem momentarily, here is the Diamond Princess bidding farewell to Mazatlan until next Wednesday. The ship has just sailed right past his favorite restaurant, La Puntilla so I know he will be momentarily distracted.
Wish I could offer solutions for the spam problem, and hoping someone else can as I create a diversion here. I understand spam laws are being instituted up north.
Attachments: April Daze in Maz 010.jpg (140 KB)


ET

Apr 21, 2004, 11:20 PM

Post #8 of 15 (972 views)

Shortcut

Re: [Uncle Donnie] Website attack

Can't Post | Private Reply

Quote
"Uncle Donnie" writes:
....I can't figure out why they're not flooding this forum with solutions and suggestions....


Charming approach.

1. Does your domain (which is what I assume you mean by your "website") have an email wildcard set to redirect all non-account email to the email box that's getting flooded? If so try changing the wildcard to a separate box (or if you don't mind losing all your "misaddressed" email, to your friendly neighborhood black hole) and seeing if this stems the flood.

2. Are you collecting your email with a POP or IMAP client? If so examine the headers on several of the seemingly identical messages and see if they're truely separate emails or you've got a configuration problem that's resulting in you pulling the same message off of your mailserver multiple times.


thfarrell


Apr 22, 2004, 6:38 AM

Post #9 of 15 (948 views)

Shortcut

Re: [Uncle Donnie] Website attack

Can't Post | Private Reply
Hi Donnie...

Answers to questions like yours are not simple.

The first thing you need to do is find out where the spam is coming from. You need an email client (the thing you use on your computer to read email) that will show you the complete "header" for messages. That will let you find out the address from which the spam is coming. You may or may not be able to contact the folks with control over that address.

So - step one: here's the way an abbreviated header looks in my email client (I've replaced identifying info with "yyyy" or "xxxx"):

-------------------------------------------+
X-Originating-IP: [206.206.100.110]
X-Originating-Email: [xxxxx@xxxxxx.com]
X-Sender: xxxxx@xxxxxx.com
From: "XXXX XXXXX" <xxxxx@xxxxxx.com>
To: yyyyy@yyyyyyy.com
Subject: Norton or MacAfee?????????????????????????????????/
Date: Thu, 22 Apr 2004 06:31:23 -0600
X-OriginalArrivalTime: 22 Apr 2004 12:31:23.0681 (UTC) FILETIME=[B92DC910:01C42865]
X-RCPT-TO: <yyyyy@yyyyyyy.com>
Status: U
-------------------------------------------+

Notice that at the beginning, it says:
Originating-IP: [206.206.100.110]
So it appears that that's the "internet address" of the sender of the message.

We can also look at a more complete form of the header:

-------------------------------------------+
Received: from hotmail.com [64.4.27.90] by mail.pvs.k12.nm.us with ESMTP
(SMTPD32-8.05) id A9462DA0126; Thu, 22 Apr 2004 07:31:50 -0600
Received: from mail pickup service by hotmail.com with Microsoft SMTPSVC;
Thu, 22 Apr 2004 05:31:23 -0700
Received: from 206.206.100.110 by xxxxx@xxxxxx.com with HTTP;
Thu, 22 Apr 2004 12:31:23 GMT
X-Originating-IP: [206.206.100.110]
X-Originating-Email: [xxxxx@xxxxxx.com]]
X-Sender: xxxxx@xxxxxx.com]
From: "XXXX XXXXX" <xxxxx@xxxxxx.com]>
To: yyyy@yyyyyyy.com
Subject: Norton or MacAfee?????????????????????????????????/
Date: Thu, 22 Apr 2004 06:31:23 -0600
Mime-Version: 1.0
Content-Type: text/plain; format=flowed
Message-ID: <BAY8-F905dBKlrWJ3fv00002767@hotmail.com>
X-OriginalArrivalTime: 22 Apr 2004 12:31:23.0681 (UTC) FILETIME=[B92DC910:01C42865]
X-RCPT-TO: <yyyy@yyyyyyy.com>
Status: U
X-UIDL: 377322898
-------------------------------------------+

Notice that this one starts out with:
Received: from hotmail.com [64.4.27.90]
so it appears that the sender used a hotmail account (though this may be spoofed or "faked") and that the email came through an email server at "internet address" 64.4.27.90.

So, now we have two good clues (the names of email accounts and email services isn't much help, they're too easy to fake), namely, the two IP numbers ("internet addresses") that we've spotted,:
64.4.27.90
206.206.100.110
We can now visit a website such as:
http://dnsstuff.com/
and paste the above addresses into, for example, the "reverse DNS" and "ip whois lookup" boxes. Doing so may give us a way to backtrack the spam.

In this case, the 64.4.27.90 address probably won't get us anywhere, because Microsoft won't cooperate unless the police and /or legal action is involved (if, say, you received a death threat or an attempt at extortion).

The 206.206.100.110 address will help, though, and notice that the "ip whois lookup" tool gives us a page with three clickable links. The middle one, to the Pojoaque Schools, gives us an address and the phone number and email address for the technical contact for the domain (me). So we can write/call him (me) and he may be able to pursue the matter.

Post a reply regarding the email headers you find on your messages and we can proceed, or you might take the next step as well, visiting the dnnstuff website to see what you come up with.

tom
---
"Beauty is in the i of the Beholder"
(Julia Mandelbrot)


esperanza

Apr 22, 2004, 7:16 AM

Post #10 of 15 (942 views)

Shortcut

Re: [Marlene] Website attack

Can't Post | Private Reply
If UD would look up from the computer and look out his window this fine morning, he'd see this glorious sight on the billowing waves of Lake Chapala. She had a heckuva time navigating the Lerma (especially there in Ocotlán, going under the bridge), but here she is:




http://www.mexicocooks.typepad.com









(This post was edited by esperanza on Apr 22, 2004, 7:17 AM)
Attachments: Queen Mary.jpg (194 KB)


Uncle Donnie

Apr 22, 2004, 7:38 AM

Post #11 of 15 (938 views)

Shortcut

Re: [ET] Website attack

Can't Post |
Hi T,

Thanks for the suggestion. I'll get with one of the few people I know who can check this for me and have him see if he can do any good with with. I appreciate the help.

No, actually the charm seems to come from the techies who dance about like crazed hottentots when faced with anything other than simple problems but who pontificate to each other in loudly and expansively about the latest, fastest, and most expensive new plug-in and then can't actually apply the new "knowledge".

Or talking down to any non-initiate who dares enter the temple of The Electronic Circle Jerk. (which I assume is what you mean by your "website")

Or those who set up a business to offer advice and service and then try to convince us that the problems we take to them are our fault. Like the three operators of a local store; Bumble, Fumble, and Huh?,one of whom writes a tech column every month.

I took my new laptop in to them to get a standard keyboard and a wireless optic mouse installed. They just couldn't get it figured out. The first visit they swore it was done. The second visit they expressed bafflement that I couldn't get it to work. The third time I took it to an adult who doesn't write a tech column and he changed a few settings and had things functioning properly within an hour. And showed me that it worked before I left the shop. And didn't treat me like the half-wit illegitimate son of the scullery maid.

Shameless self-promotion:
http://www.headformexico.com


Uncle Donnie

Apr 22, 2004, 7:42 AM

Post #12 of 15 (935 views)

Shortcut

Re: [esperanza] Website attack

Can't Post |
I DID see that Baby, but I thought I was in in a peyote flashback! Good to know that more than one of us has escaped long-term hospitalization.

Shameless self-promotion:
http://www.headformexico.com


Uncle Donnie

Apr 22, 2004, 8:05 AM

Post #13 of 15 (931 views)

Shortcut

Re: [thfarrell] Website attack

Can't Post |
Hi Tom,

That cat and I have a lot in common this mornin'.

Thanks for your help. As I told ET I'm going to turn this over to someone who can interpret and apply it. At least now I can walk in with some suggestions. Earthlink is evidently as stumped as I am.

Of the offline replies I got the most eye-opening may have been from a non-tech type with whom I exchange e-mails from time to time. This is how computer illiterate I am: he assumed that I had a anti-spam program of some sort protecting the site. I have no clue since I don't do anything with the site aside from compiling content.

To the logical side of my untrained brain that seems to be the first thing I need to investigate along with implementing the suggestions you guys offered.

The problem down here is that we have too many "experts" who ae more than willing to fleece those of us who type with one finger.

I had a computer built by one of the Mexican locals. Slow, noisy, lots of problems. A team of gringo youngsters checked it out and discovered that outdated and outmoded parts had been used so they supercharged it for me. By the time (days and days later---house call after house call later) that they had it functioning again, with 556(?) whatevers of memory installed (which others told me was not at all essential for my meager needs) along with other nickel and dimings, I had ended up with an $1,100+ (actually $1,500+ if you add in the original cost of the "custom" job) very large paperweight.

I finally gave up and gave it away.

Again, I appreciate the help you guys offered and I'll check back in after the problem gets solved to let you know more about the specifics of this case.

Shameless self-promotion:
http://www.headformexico.com


tfyoung


Apr 22, 2004, 5:07 PM

Post #14 of 15 (904 views)

Shortcut

Re: [Uncle Donnie] Website attack

Can't Post | Private Reply
Donnie,
My son uses a thing called Mailwasher. I believe there is a free version of it. Here is their website.

http://www.mailwasher.net/

Seems to work okay for the boy, but his mail box probably isn't as high-traffic as yours.


Uncle Donnie

Apr 22, 2004, 9:12 PM

Post #15 of 15 (891 views)

Shortcut

Re: [tfyoung] Website attack

Can't Post |
Thank you very much. I'll look at this. Actually this and the most logical question/suggestion I've received seem to be the most straightforward and the simplest way to begin my diagnostic search.

The offline question: Do you have a SPAM guard/filter on your website. I called for the answer and found out that NO, I don't.

It looks as though my first two steps are laid out, then on to the more techno savvy stuff if those two bomb. I'll let you know how it shakes out. This is a holdover from that Doom Worm (correct ID?) of a few months back I think.

Shameless self-promotion:
http://www.headformexico.com
 
 
 
Search for (advanced search) Powered by Gossamer Forum v.1.2.4