WebProWorld Part of WebProNews.com
Page One Link To Us Edit Profile Private Messages Archives FAQ RSS Feeds  
 

Go Back   WebProWorld > Webmaster, IT and Security Discussion > Internet Security Discussion Forum
Subscribe to the Newsletter FREE!


Register FAQ Members List Calendar Arcade Chatbox Mark Forums Read

Internet Security Discussion Forum This forum is for the discussion of security related issues. If you find a new Phishing scheme, spyware, virus or malicious site - let us know about it. If any of the above found you... here's where you ask for help.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 07-22-2004, 03:16 PM
mikmik's Avatar
WebProWorld 1,000+ Club
 

Join Date: Aug 2003
Location: Edmonton, AB, Canada
Posts: 3,406
mikmik RepRank 1
Default Mailer Daemon

I got an extremely strange email today with the subject line and body text containing one word: 'test'.

Here is the message source that I viewed (before opening it):
Quote:
X-Message-Info: 6sSXyD95QpUpF+g+2nALC/QSdHs+hw3z
Received: from linux.local ([207.6.202.47]) by mc5-f4.hotmail.com with Microsoft SMTPSVC(5.0.2195.6824);
Thu, 22 Jul 2004 04:53:38 -0700
Received: by linux.local (Postfix, from userid 30)
id 2F4FD1C138; Thu, 22 Jul 2004 04:56:20 -0700 (PDT)
To: mykle4@hotmail.com
Subject: test
Message-Id: <20040722115620.2F4FD1C138@linux.local>
Date: Thu, 22 Jul 2004 04:56:20 -0700 (PDT)
From: wwwrun@linux.local (WWW daemon apache)
Return-Path: wwwrun@linux.local
X-OriginalArrivalTime: 22 Jul 2004 11:53:38.0271 (UTC) FILETIME=[867AE6F0:01C46FE2]

test
I ran a lookup on '207.6.202.47' and got
Quote:
207.6.202.47 [PSI.COM or ISTAR0006] appears to be located at: OTTAWA, ONTARIO, CA.
which led me directly to http://www.psinet.com/.
These people provide dedicated internet access
Quote:
PSINet's Dedicated Access services offer you superior performance for your business Internet connections. Your traffic will ride on Cogent's all optical fiber backbone, ensuring maximum speed and reliability. Two connectivity options are available:

Dedicated T1 Internet Connectivity at 1.5 Mbps
Dedicated T3 Internet Connectivity at 45 Mbps
for business accounts, etc, not cheap stuff, I am sure.
Funny thing about this is that I got to a hotmail account, funny I got it at all.
Did anyone else get anything like this?

I will email PSI with this as well.
__________________
What I am is what I am, are you what you are, or what.
Eddie Brickel
Reply With Quote
  #2 (permalink)  
Old 07-22-2004, 04:04 PM
wenwilder's Avatar
WebProWorld 1,000+ Club
 

Join Date: Jul 2003
Location: Nebraska US
Posts: 2,176
wenwilder RepRank 2wenwilder RepRank 2
Default

Did it come with an attachment mik? An email with one word in it, these days, usually signifies a virus. "Mailer Daemon" is another one. If it didn't come with an attachment then more than likely it was cleaned somewhere along the way.

Just remember the origination of the email could have came from an infected machine. Emailing it to the company is a smart move though. But then you know that already lol



*congrats on mod status by the way ;)
__________________
Forum Rules
"Cat washing IS a martial art."
"Remember Today IS Yesterdays Tomorrow"
Reply With Quote
  #3 (permalink)  
Old 07-22-2004, 09:00 PM
mikmik's Avatar
WebProWorld 1,000+ Club
 

Join Date: Aug 2003
Location: Edmonton, AB, Canada
Posts: 3,406
mikmik RepRank 1
Default

They replied to me that I emailed the wrong department and to go "dept name"
But I already had an email from "dept name" saying that I was not a customer and would be accorded a 'class three' priority and they would try to get to my trouble ticket within 48 hrs!
Then they gave me a trouble ticket number LOL

I talked it over with mushroom, and it looks like someone that has a dedicated line with PSI (hmmm, I am getting a feeling...) was testing their mail server and forgot to stop the general mailing list from getting this.
I figure it is one of the newsletters I subscribe to, I also got one of these on another account on MY Linux machine, but I thought I must have sent it to myself.
Oh well, another mystery solved.
Good work, WW. Hey, that rhymes with 'double-you-double-you' :O)


*thanks, by the way! Can I edit some of your posts?
__________________
What I am is what I am, are you what you are, or what.
Eddie Brickel
Reply With Quote
Reply

  WebProWorld > Webmaster, IT and Security Discussion > Internet Security Discussion Forum
Tags: ,



Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Search Engine Optimization by vBSEO 3.2.0