Security Basics mailing list archives

Re: Compromised email account?


From: William Taylor <WTaylor () FusionStorm com>
Date: Thu, 10 Feb 2011 14:29:21 -0800

Keep in mind that strong passwords are still compromised through social engineering & shoulder surfing - so better safe 
than sorry when it comes to changing your password !

----- Original Message -----
From: listbounce () securityfocus com <listbounce () securityfocus com>
To: Adam Pal <pal_adam () gmx net>
Cc: security-basics () securityfocus com <security-basics () securityfocus com>
Sent: Wed Feb 09 03:12:22 2011
Subject: Re: Compromised email account?

Hi,
Thanks for all the feedback. It is greatly appreciated. I do not think
it is a spoofing attack as I have items in my sent folder as well as
drafts.

I also highly doubt it was because of a weak password. My password was
14 characters and consisted of upper case and lower case aplhanumeric
characters and wasn't based on a dictionary word. I have always been
very careful with passwords and usernames.

Jacob.

On Feb 9, 2011, at 21:59, Adam Pal <pal_adam () gmx net> wrote:

Hello Jacob,

You could ask some logs or evidence from your provider (i doubt they
will do).
However SMTP is not very secure, i.e. if send without authentication
is accepted
the FROM is falsified the server will reply to the FROM.


--
Best regards,
Adam Pal

Tuesday, February 8, 2011, 4:14:10 AM, you wrote:

<==============Original message text===============
JB> Hi,
JB> After awaking this morning, I found my inbox riddled with failed
JB> delivery notices from my service provider. Wierd thing is I
haven't
JB> sent emails from the address in weeks.
JB> Does this mean my inbox has been compromised? If so, is there
anything
JB> I can do to reclaim it and maintain it without this issue occuring
JB> again?

JB> Jacob.

JB>
---
---------------------------------------------------------------------
JB> Securing Apache Web Server with thawte Digital Certificate
JB> In this guide we examine the importance of Apache-SSL and who
JB> needs an SSL certificate.  We look at how SSL works, how it
JB> benefits your company and how your customers can tell if a site is
JB> secure. You will find out how to test, purchase, install and use a
JB> thawte Digital Certificate on your Apache web server. Throughout,
JB> best practices for set-up are highlighted to help you ensure
JB> efficient ongoing management of your encryption keys and digital
certificates.

JB> http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
JB>
---
---------------------------------------------------------------------


<===========End of original message text===========




------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how 
it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, 
install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are 
highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


CONFIDENTIAL. This e-mail and any attachment, is a confidential communication covered by work-product, and the 
Electronic Communications Privacy Act, 18 U.S.C. §§ 2510-2521. If you received this message in error, please notify me 
by replying to this email message and destroy (delete) the original.  Thank you.

Current thread: