OT: My neighbour's been hacked

Sep 07, 2021 Last reply: 4 years ago 32 Replies

In message snipped-for-privacy@esprimo.zbmc.eu>, at 19:26:44 on Tue, 7 Sep

2021, Chris Green snipped-for-privacy@isbd.net remarked:

Yes, you can set it, but many large ISPs will reject it if it's not from a domain they know you have registered (an interest, not necessarily hosting) with them.

In message snipped-for-privacy@iridium.wfdf, at 19:45:42 on Tue, 7 Sep

2021, Jim Jacks>> >>>>

It's not trivial to set up to ensure that the majority of client-end ISPs don't reject as spam.

FAOD, vanishingly few members of the public run their own inbound SMTP servers.

While I still have that domain, about ten years ago I experimentally switched off the <list of users> and thus started receiving <anything>, and it was in the region of 20,000 a day.

That's spear phishing, and if you are the victim of that, you have far bigger problems than just too many emails to delete.

While often true, it's worth noting that this is optional - it does require the person administering the email for the domain to know about things like SPF records, DKIM and DMARC etc

Many ISP email servers will object to sending email from a domain that does not actually exist without any further instruction.

Indeed. Getting mail though to MS owned domains (outlook, hotmail, live etc) is getting increasingly difficult.

Scammers tend to prefer using other people's compromised accounts - then little traces back to them.

Spoofing from addresses has got harder, hence why many scam emails come from one email address, but the specify something completely different in the (optional) "reply to" address.

????? Dont understand. Can you clarify, point out what I need to be alert for?

In your example, someone researching potential targeted email addresses (rather than just guessing) which means they likely have some specific reason to want to phish *you*, rather than someone at random.

If anything it sounds like a misguided attempt to target real people previously employed by the former owner of the domain, or more likely just mailing lists or spam lists those people were on?

In message snipped-for-privacy@mid.individual.net>, at 08:33:12 on Fri, 10 Sep

2021, Andy Burns snipped-for-privacy@andyburns.uk remarked:

That would be spear-phishing those people, and giving them something to worry about. Chris mentioned using wayback machine to research employees of the former owner.

It'd be bad luck if there was also a chris@-the-former-owner, and Chris was rejecting all emails not to chris@ (or another short list) while publicising his own email address as chris@-him-the-new-owner.

I presumed he was only searching wayback to see if the emails he was receiving (to a catch-all account for the domain) corresponded to accounts that previously existed.

I don't see where @the-former-owner or @the-new-owner comes into it, surely it's @the-same-domain in all cases?

It could be - but it could also simply be they had their work email addresses registered with various suppliers and hence were on mailing lists. Plenty of email marketers are very sloppy at handling bound messages and remove / unsubscribe requests.

Common names will also attract more traditional spam.

That's what he was doing, but not a spear-phisher, and those are the folks whose activities needed explaining.

Yes, the domain name is the same.

For example a friend of mine used to own goldfish.com because that was his hobby and he was an extremely early adopter of vanity domain names. (and worked in the ISP trade so self-hosting it was trivial).

Let's say his name was Chris, and he set it up to bounce most email other than to snipped-for-privacy@golfish.com [aka chris@the-former-owner]

Fast forward to a credit card company who later made him an offer he couldn't refuse, and became the new-owner.

If they had a person at HQ whose email address would normally have been snipped-for-privacy@goldfish.com [aka chris@the-new-owner], that would clearly receive any of the spam/phishing my friend might have been previously suffering from.

[As a remedial measure, maybe new-chris should think about changing email address slightly, so that stuff to plain 'chris' could be bounced]

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required