Click Here



Post New Topic  Post A Reply
my profile | register | search | faq | forum home
  next oldest topic   next newest topic
»  :[ Q3Arena.com Message Board ]:   » The Lounge   » decode this header info...

UBBFriend: Email this page to someone!    
Author Topic: decode this header info...
burble
Sarge
Member # 1190

Member Rated:

posted 02-17-2003 01:14 AM     Profile for burble   Author's Homepage     Send New Private Message   Edit/Delete Post   Reply With Quote
i'm getting about 5-10 emails a day stating either A) undeliverable address or B) message filtered due to presense of virus.

i did not send any mails. my computer does not have a virus. for some reason, though, my email is being used as the return address by one. i'm assuming some dipshit had me in their address book and that's what's causing this. here are two random mails, would anyone like to tell me any specifics? i don't know how these work...every one has a different 'from' field at the bottom, some of them are emails i recognize from another message board.


ramdom mail 1:

Return-path:
Received: from tcp_large_isp-daemon.mtaout04.icomcast.net by
mtaout04.icomcast.net
(iPlanet Messaging Server 5.2 HotFix 1.09 (built Jan 7 2003))
id <0HAF0068P8J85N@mtaout04.icomcast.net>; Sun,
16 Feb 2003 16:47:33 -0500 (EST)
Received: from Ztyyms (pcp01379926pcs.levtwn01.pa.comcast.net [68.81.92.153])
by mtaout04.icomcast.net
(iPlanet Messaging Server 5.2 HotFix 1.09 (built Jan 7 2003))
with SMTP id <0HAF0066B8IZ79@mtaout04.icomcast.net> for
shadydre187@hotmail.com; Sun, 16 Feb 2003 16:47:32 -0500 (EST)
Date: Sun, 16 Feb 2003 16:47:24 -0500 (EST)
Date-warning: Date header was inserted by mtaout04.icomcast.net
From: danandjen13
Subject: Re:shadydre187,meeting notice
To: shadydre187@hotmail.com
Message-id: <0HAF0066C8IZ79@mtaout04.icomcast.net>
MIME-version: 1.0
Content-type: multipart/alternative;
boundary="Boundary_(ID_fimSAjG0FrPJzzDIyQJknw)"

Your message cannot be delivered to the following recipients:

Recipient address: shadydre187@hotmail.com
Reason: Remote SMTP server has rejected address
Diagnostic code: smtp;550 Requested action not taken: mailbox unavailable
Remote system: dns;mx4.hotmail.com (TCP|24.153.64.230|57782|65.54.253.230|25)


--------------------------------------------------------------------------------


Return-path:
Received: from tcp_large_isp-daemon.mtaout04.icomcast.net by
mtaout04.icomcast.net
(iPlanet Messaging Server 5.2 HotFix 1.09 (built Jan 7 2003))
id <0HAF0068P8J85N@mtaout04.icomcast.net>; Sun,
16 Feb 2003 16:47:33 -0500 (EST)
Received: from Ztyyms (pcp01379926pcs.levtwn01.pa.comcast.net [68.81.92.153])
by mtaout04.icomcast.net
(iPlanet Messaging Server 5.2 HotFix 1.09 (built Jan 7 2003))
with SMTP id <0HAF0066B8IZ79@mtaout04.icomcast.net> for
shadydre187@hotmail.com; Sun, 16 Feb 2003 16:47:32 -0500 (EST)
Date: Sun, 16 Feb 2003 16:47:24 -0500 (EST)
Date-warning: Date header was inserted by mtaout04.icomcast.net
From: danandjen13
Subject: Re:shadydre187,meeting notice
To: shadydre187@hotmail.com
Message-id: <0HAF0066C8IZ79@mtaout04.icomcast.net>
MIME-version: 1.0

random mail 2:

Return-path:
Received: from tcp-daemon.mtaout05.icomcast.net by mtaout05.icomcast.net
(iPlanet Messaging Server 5.2 HotFix 1.09 (built Jan 7 2003))
id <0HAF00J4K6DQ8E@mtaout05.icomcast.net>; Sun,
16 Feb 2003 16:01:02 -0500 (EST)
Received: from Lddekilo (pcp01379926pcs.levtwn01.pa.comcast.net [68.81.92.153])
by mtaout05.icomcast.net
(iPlanet Messaging Server 5.2 HotFix 1.09 (built Jan 7 2003))
with SMTP id <0HAF00I9H6DE6G@mtaout05.icomcast.net> for golden@esolwz.com;
Sun, 16 Feb 2003 16:01:01 -0500 (EST)
Date: Sun, 16 Feb 2003 16:00:50 -0500 (EST)
Date-warning: Date header was inserted by mtaout05.icomcast.net
From: Dallasgirl54
Subject: A special nice game
To: golden@esolwz.com
Message-id: <0HAF00I9J6DE6G@mtaout05.icomcast.net>
MIME-version: 1.0
Content-type: multipart/alternative;
boundary="Boundary_(ID_jrMtLZ3xBBlWrgJPlKxZ7g)"

Your message cannot be delivered to the following recipients:

Recipient address: golden@esolwz.com
Reason: Illegal host/domain name found


--------------------------------------------------------------------------------


Return-path:
Received: from tcp-daemon.mtaout05.icomcast.net by mtaout05.icomcast.net
(iPlanet Messaging Server 5.2 HotFix 1.09 (built Jan 7 2003))
id <0HAF00J4K6DQ8E@mtaout05.icomcast.net>; Sun,
16 Feb 2003 16:01:02 -0500 (EST)
Received: from Lddekilo (pcp01379926pcs.levtwn01.pa.comcast.net [68.81.92.153])
by mtaout05.icomcast.net
(iPlanet Messaging Server 5.2 HotFix 1.09 (built Jan 7 2003))
with SMTP id <0HAF00I9H6DE6G@mtaout05.icomcast.net> for golden@esolwz.com;
Sun, 16 Feb 2003 16:01:01 -0500 (EST)
Date: Sun, 16 Feb 2003 16:00:50 -0500 (EST)
Date-warning: Date header was inserted by mtaout05.icomcast.net
From: Dallasgirl54
Subject: A special nice game
To: golden@esolwz.com
Message-id: <0HAF00I9J6DE6G@mtaout05.icomcast.net>
MIME-version: 1.0

could someone tell me if these are originating from the same person?


Posts: 528 | From: Nashville, TN | Registered: Nov 1999  |  IP: Logged
Wolfie
Sarge
Member # 1698

Member Rated:

posted 02-17-2003 07:22 AM     Profile for Wolfie   Author's Homepage     Send New Private Message   Edit/Delete Post   Reply With Quote
I have no idea what I'm talking about, but I'm guessing that

Received: from Ztyyms (pcp01379926pcs.levtwn01.pa.comcast.net [68.81.92.153])
by mtaout04.icomcast.net (mail 1)

and

Received: from Lddekilo (pcp01379926pcs.levtwn01.pa.comcast.net [68.81.92.153])
by mtaout05.icomcast.net (mail 2)

are significant, as well as

Date-warning: Date header was inserted by mtaout04.icomcast.net (Mail 1)

and

Date-warning: Date header was inserted by mtaout05.icomcast.net (Mail 2)

But I'm just guessing. It could be your mail server that's generating the same addresses.

[ 02-17-2003: Message edited by: Wolfie ]

--------------------

Draw a crazy picture,
Write a nutty poem,
Sing a mumble-grumble song,
Whistle through your comb.
Do a loony-goony dance
'Cross the kitchen floor,
Put something silly in the world
That ain't been there before.
-Put Something In, Shel Silverstein


Posts: 786 | From: Cold place that rains all the time | Registered: Jan 2000  |  IP: Logged
Cacophonous
Sarge
Member # 19

Member Rated:

posted 02-17-2003 08:48 AM     Profile for Cacophonous   Author's Homepage     Send New Private Message   Edit/Delete Post   Reply With Quote
You do have a virus.

--------------------

...


Posts: 5571 | From: Yes | Registered: Jun 1999  |  IP: Logged
xanthan
Sarge
Member # 35

Member Rated:

posted 02-17-2003 10:07 AM     Profile for xanthan   Author's Homepage     Send New Private Message   Edit/Delete Post   Reply With Quote
I think you have a virus.

--------------------

Im not really here


Posts: 1051 | From: US | Registered: Jun 1999  |  IP: Logged
burble
Sarge
Member # 1190

Member Rated:

posted 02-17-2003 01:58 PM     Profile for burble   Author's Homepage     Send New Private Message   Edit/Delete Post   Reply With Quote
then where the hell are the random 'from' addresses coming from? most of them are people i know but do not have in my address book.

and 3 different scanners have picked up nothing.


Posts: 528 | From: Nashville, TN | Registered: Nov 1999  |  IP: Logged
Snag
Sarge
Member # 992

Member Rated:

posted 02-17-2003 06:51 PM     Profile for Snag   Author's Homepage     Send New Private Message   Edit/Delete Post   Reply With Quote
forward that off to the abuse dept. of your isp. E-Mail headers can easily be spoofed. Just a week or so ago, my computer was off for a couple days. I checked my e-mail via the webmail interface, not using pop3, during this time. Came home, re-installed windows. Now when I checked again, I had one of those said emails...but this one had a batch file and a vbscript file attached. I know I never had a chance to send those and I know that the timeframe and the fact I checked my email via the web portal back me up there. Just delete the e-mails, keep your virus scan up to date etc...as long as YOU have taken your precautions, chances are none of that originated from you. Remember, also, it could even be something on your isps end. We all know the stories of isps
Posts: 2606 | From: Canada | Registered: Nov 1999  |  IP: Logged

All times are ET (US)  

Post New Topic  Post A Reply Close Topic    Move Topic    Delete Topic next oldest topic   next newest topic
Hop To:

Contact Us | Q3Arena.Com

Powered by Infopop Corporation
Ultimate Bulletin Board 6.04d