Security Basics mailing list archives

RE: Web mail intercepted! How?


From: Murad Talukdar <talukdar_m () subway com>
Date: Fri, 05 Aug 2005 09:15:07 +1000

Check the headers first. Do they give any info on the route the mail has
taken. Compare them with the headers from different recipients.

What is physical/login security like on the machine itself?

-----Original Message-----
From: pagoda33 () sbcglobal net [mailto:pagoda33 () sbcglobal net] 
Sent: Thursday, August 04, 2005 1:57 PM
To: security-basics () securityfocus com
Subject: Web mail intercepted! How?

Someone at our company sent email using a free Web mail service from a
workstation inside our network. The message was somehow intercepted by a
third party, was forwarded to an unknown number of people, and found its way
back to the sender...

Needless to say, the sender is quite upset ...

We don't know whether the Web mail account was compromised from the outside,
or if someone is packet-sniffing or keylogging from inside the network.

We're going to start looking tomorrow... any ideas on how to proceed?


Current thread: