Old 4th April 2005, 04:19   #1
xzxzzx
Forum King
 
xzxzzx's Avatar
 
Join Date: Aug 2002
Posts: 7,254
Spam that's not spam?

Ok, I got this message. It looks like spam, but WTF? No link, no hidden message, no nothing. Here's the whole thing, including headers:

code:
X-Message-Status: n
X-SID-PRA: Dat Alvi <CatherineBlackley@user-0c90prd.cable.mindspring.com>
X-SID-Result: TempError
X-Message-Info: 6sSXyD95QpXRZ+yO9O9I01eT2MlQKVWXme/MfWRkXEo=
Received: from mc4-f18.hotmail.com ([65.54.190.154]) by imc3-s24.hotmail.com with Microsoft SMTPSVC(6.0.3790.211);
Sat, 2 Apr 2005 17:25:30 -0800
Received: from user-0c90prd.cable.mindspring.com ([24.144.103.109]) by mc4-f18.hotmail.com with Microsoft SMTPSVC(6.0.3790.211);
Sat, 2 Apr 2005 17:25:29 -0800
Date: Sun, 03 Apr 2005 01:11:51 +0000
From: Dat Alvi <CatherineBlackley@user-0c90prd.cable.mindspring.com>
To: ********@hotmail.com
Subject: =?iso-8859-1?B?LQ==?=
MIME-Version: 1.0
Content-Type: text/plain; charset=iso-8859-1
Content-Transfer-Encoding: 7bit
Return-Path: CatherineBlackley@user-0c90prd.cable.mindspring.com
Message-ID: <MC4-F18SBWYf5UPHvAo00026fc9@mc4-f18.hotmail.com>
X-OriginalArrivalTime: 03 Apr 2005 01:25:30.0296 (UTC) FILETIME=[06088B80:01C537EC]

Bobbi Aversa


Freedom of speech is the basic freedom of humanity. When you've lost that, you've lost everything.
1\/\/4y 34|<$p4y 1gp4y 33714y, 0d4y 0uy4y? | Roses are #FF0000; Violets are #0000FF; chown -R ${YOU} ~/base
The DMCA. It really is that bad. : Count for your life.
xzxzzx is offline   Reply With Quote
Old 4th April 2005, 04:21   #2
drewbar
Sawg 2.0
Major Dude
 
Join Date: Mar 2004
Posts: 5,916
Well, looks like sonone is trying to run a SMTP server off their cable modem. Maybe misconfigured it, was was testing it or something like that.

Count with us!
Jan 1st, 12AM (PST, GMT -8) 2010 - 282,246
drewbar is offline   Reply With Quote
Old 4th April 2005, 04:34   #3
zootm
Forum King
 
zootm's Avatar
 
Join Date: Jan 2002
Location: the nether reaches of bonnie scotland
Posts: 13,375
I agree. The DNS is a home user hostname, and it was using Microsoft's SMTP stuff it looks like.

I think it's a fair bet that the Windows username that was being used was "CatherineBlackley" as well

zootm is offline   Reply With Quote
Old 4th April 2005, 06:09   #4
griffinn
Court Jester
(Forum King)
 
griffinn's Avatar
 
Join Date: May 2000
Location: Your local toystore
Posts: 3,501
Send a message via ICQ to griffinn
I never get to see that sort of stuff. dnsbl.net.au and sbl-xbl.spamhaus.org blocked them all.

The smiley slot machine! | Quotable Blog
griffinn is offline   Reply With Quote
Old 4th April 2005, 06:30   #5
MegaRock
Forum King
 
MegaRock's Avatar
 
Join Date: Jun 2003
Location: Inside my water bong
Posts: 6,865
Send a message via ICQ to MegaRock Send a message via Yahoo to MegaRock
Actually most of these are hijacked smtp servers that someone will use to send 'test' messages. If no rejection message comes back they know the address is still receiving mail and can be sold.

Megarock Radio - St. Louis Since 1998!
Don't click this link!
Corporate Radio Sucks! No suits, all rock!
MegaRock is offline   Reply With Quote
Old 4th April 2005, 09:39   #6
PulseDriver
w3 addict
(Major Dude)
 
PulseDriver's Avatar
 
Join Date: May 2004
Location: Norway
Posts: 1,806
Or maybe they tried a test to use the

To: ********@hotmail.com

Maybe there will come a spam later from this adress. Unless that was editied on purpose.

09 F9 11 01 9D 74 E8 5B D8 41 56 C3 63 56 81 C0
PulseDriver is offline   Reply With Quote
Old 4th April 2005, 09:47   #7
Leonhart
Senior Member
 
Leonhart's Avatar
 
Join Date: Mar 2005
Location: England
Posts: 312
Send a message via AIM to Leonhart Send a message via Yahoo to Leonhart
Weird never seen anything like that before.

"To Be Forgotten Is Worse Than Death"
Leonhart is offline   Reply With Quote
Old 4th April 2005, 15:11   #8
xzxzzx
Forum King
 
xzxzzx's Avatar
 
Join Date: Aug 2002
Posts: 7,254
Quote:
Originally posted by PulseDriver
To: ********@hotmail.com

Maybe there will come a spam later from this adress. Unless that was editied on purpose.
Yeah, that's edited.

Quote:
Originally posted by MegaRock
Actually most of these are hijacked smtp servers that someone will use to send 'test' messages. If no rejection message comes back they know the address is still receiving mail and can be sold.
That makes sense. Hotmail really should've blocked this email.

Freedom of speech is the basic freedom of humanity. When you've lost that, you've lost everything.
1\/\/4y 34|<$p4y 1gp4y 33714y, 0d4y 0uy4y? | Roses are #FF0000; Violets are #0000FF; chown -R ${YOU} ~/base
The DMCA. It really is that bad. : Count for your life.
xzxzzx is offline   Reply With Quote
Reply
Go Back   Winamp & Shoutcast Forums > Community Center > General Discussions

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump