Solved

Spam or system attack - strange email

Posted on 2004-04-12
11
291 Views
Last Modified: 2010-04-11
Hi!

I got a strange email today. Within this email is a link to a site I own, but as far as I can see, the link goes to a url on my server that does not exist.
I don't want to share too much information about this issue right here now. Would somebody assist me with this problem privatly? I already talked to my server admins about this, but I'd like to have a 2nd opinion.

I don't know if it's common to keep things private here, but I'm very concerned and don't want to share info to too many ppl (atm).

Greetings,

su-n
0
Comment
Question by:su-n
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 4
  • 2
  • +1
11 Comments
 
LVL 49

Expert Comment

by:sunray_2003
ID: 10806721
Hey have you checked the IP address from where the email has come looking at the header of the email ..

May be a spam but looking at that email, your system admin would be a better to position to  know where it has come from and what it is..

Check for virus and spyware in your system since you had checked that email and possible spyware got downloaded by that link ..
0
 
LVL 49

Expert Comment

by:sunray_2003
ID: 10806832
0
 
LVL 1

Author Comment

by:su-n
ID: 10806886
The mail is Virus/Spyware free. What I'm beeing concerned about is that my url is in this email and I don't want others to get such a email with my server beeing abused.
Thanks for the links.
0
Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 49

Expert Comment

by:sunray_2003
ID: 10806894
Have you not figured out yet who has sent you that email ?

Only somone who knows about this url would have sent it .. or it might be some worm spamming all inboxes with the email and your link. Make sure there is anti-spam software installed ... Talk with your system admin
0
 
LVL 1

Author Comment

by:su-n
ID: 10806924
as your writing about "inbox" ... the url is:
www.URL.de/inbox/EMAIL.NAME/read.php?sessionid-28973 
0
 
LVL 49

Assisted Solution

by:sunray_2003
sunray_2003 earned 150 total points
ID: 10806937
Are you using microsoft exchange or outlook web access ? I donot think anyone can check your inbox until they have logged into it with username and password of yours
0
 
LVL 1

Author Comment

by:su-n
ID: 10806967
My server is a Redhat server, at home I use Outlook 2003. But I have a Web-based Email disabled for all domains on the server.
0
 
LVL 24

Expert Comment

by:SunBow
ID: 10807572
> Would somebody assist me with this problem privatly?

not permitted

> I don't want to share too much information about this issue right here now.

wise

> if it's common to keep things private here

This is (necessarily) public

> the link goes to a url on my server that does not exist.

Possible programming bug or red herring (often for spam, but if not, you'f best check, and recheck your internal security, especially if you've got ftp inbound.  It could be guesswork, but you've not indicated that.

>  I don't want others to get such a email with my server beeing abused.

Publication of EM addy is like solicitation of spam through harvester.
0
 
LVL 24

Assisted Solution

by:SunBow
SunBow earned 50 total points
ID: 10807591
> I already talked to my server admins about this, but I'd like to have a 2nd opinion.

Of course, you could give us a little something on their opinion to give us a better idea about what's going on there.
0
 
LVL 5

Accepted Solution

by:
Luniz2k1 earned 300 total points
ID: 10807958
This is the work of the W32.Netsky.P@mm worm.  It sends out e-mails with contents such as:

If the message will not displayed automatically,
follow the link to read the delivered message.

Received message is available at:
www.yourdomainnamehere.com/inbox/someuser/read.php?sessionid-5935

The e-mail message has an attachment on it that contains the worm also.  I have received many e-mails from this worm and Norton A/V has cleaned it every time.  I work at a plant that has 800+ employees and 350+ client PC's and many of them have called asking about these e-mails.  As long as your A/V is up to date, you have nothing to worry about.
0
 
LVL 1

Author Comment

by:su-n
ID: 10809059
Yes, that's exactly what the msg looks like! Thanks.

How is this message with "yourdomainnamehere.com" and "/someuser" generated? Does that mean, I am infected? I don't think so, coz my nav is updated regularly as well as I scan my drives regularly, too.
Or does it mean, s.o. who has my info on his computer is affected? Or does this worm crawls websites and catches email addys?

>SunBow: no guesswork, definately.

Thanks a lot for all your help!
0

Featured Post

What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Here's a look at newsworthy articles and community happenings during the last month.
Make the most of your online learning experience.
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…
Suggested Courses
Course of the Month3 days, 23 hours left to enroll

630 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question