Full Disclosure mailing list archives

Re: Fwd: YOUR PAYPAL.COM ACCOUNT EXPIRES


From: Rachael Treu <rara () navigo com>
Date: Fri, 14 Nov 2003 12:42:29 -0600

On Fri, Nov 14, 2003 at 12:39:34AM -0700, Irwan Hadi said something to the effect of:
On Thu, Nov 13, 2003 at 07:44:27PM -0600, Rachael Treu wrote:

Delete it or forward it to abuse () yahoo com.

Headers (at least on the copy I received) identify the man behind
the curtain as...

From jcsjj5 () yahoo com  Thu Nov 13 17:28:51 2003
Return-Path: <jcsjj5 () yahoo com>
Received: from 81.249.20.142 (APuteaux-111-1-5-142.w81-249.abo.wanadoo.fr
+[81.249.20.142])

I don't think yahoo.com has something to do here, since the culprit is one user from wanadoo.fr
He just spoofed some email @yahoo.com

Agreed, but I still forward to yahoo.com to make them aware, as they're
likely to receive complaints from folks that briefly parse the headers.

Then again, I'm a security engineer for a provider that is frequently
deluged by such clamoring, so that, indeed, might be just me... ;)

ymmv,
--ra

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html

-- 
K. Rachael Treu, CISSP     rara () navigo com
..Fata viam invenient..

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: