<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel> 

	<title>Comments on: Help me snatch a hacker/spammer</title>
	<link>http://ask.metafilter.com/79859/Help-me-snatch-a-hackerspammer/</link>
	<description>Comments on Ask MetaFilter post Help me snatch a hacker/spammer</description>
	<pubDate>Mon, 31 Dec 2007 16:27:40 -0800</pubDate>
	<lastBuildDate>Mon, 31 Dec 2007 16:27:40 -0800</lastBuildDate>
	<language>en-us</language>
	<docs>http://blogs.law.harvard.edu/tech/rss</docs>
	<ttl>60</ttl>

	<item>
		<title>Question: Help me snatch a hacker/spammer</title>
		<link>http://ask.metafilter.com/79859/Help-me-snatch-a-hackerspammer</link>	
		<description>My hotmail acct has been hacked/cracked and is being used to spam people including a few MeFites.  I&apos;m pissed and concerned.  Please hope me! &lt;br /&gt;&lt;br /&gt; I&apos;ve changed my password to something I think is pretty uncrackable but it&apos;s still happening.  &lt;br&gt;
&lt;br&gt;
Ultimately, I know, I should just use a g-mail acct.  But in the mean time, what can I do to investigate, complain and secure the info that exists there in my acct?&lt;br&gt;
&lt;br&gt;
It&apos;s also odd that at least one Mefite has been spammed who I&apos;ve never had contacted with hotmail.  So I believe that this might be MeFi related too.&lt;br&gt;
&lt;br&gt;
p.s.  Should I post a PSA to MeTa to let folks know that I&apos;m not spamming them?</description>
		<guid isPermaLink="false">post:ask.metafilter.com,2007:site.79859</guid>
		<pubDate>Mon, 31 Dec 2007 16:24:09 -0800</pubDate>
		<dc:creator>snsranch</dc:creator>
		
			<category>hacked</category>
		
			<category>cracked</category>
		
			<category>password</category>
		
			<category>spam</category>
		
			<category>hotmail</category>
		
	</item> <item>
		<title>By: timmins</title>
		<link>http://ask.metafilter.com/79859/Help-me-snatch-a-hackerspammer#1185080</link>	
		<description>I would check to see what is listed as the backup email address for password recovery. In this case, you may change your password a million times but the offender can retrieve it if they have their account listed as the backup.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.79859-1185080</guid>
		<pubDate>Mon, 31 Dec 2007 16:27:40 -0800</pubDate>
		<dc:creator>timmins</dc:creator>
	</item><item>
		<title>By: sanko</title>
		<link>http://ask.metafilter.com/79859/Help-me-snatch-a-hackerspammer#1185085</link>	
		<description>Are you certain that the email is coming from Hotmail and not from someone spoofing the headers?  Can you ask someone who&apos;s received the spam to take a look?</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.79859-1185085</guid>
		<pubDate>Mon, 31 Dec 2007 16:30:02 -0800</pubDate>
		<dc:creator>sanko</dc:creator>
	</item><item>
		<title>By: krisjohn</title>
		<link>http://ask.metafilter.com/79859/Help-me-snatch-a-hackerspammer#1185086</link>	
		<description>Yeah, sounds like you&apos;re being &lt;a href=&quot;http://en.wikipedia.org/wiki/Joe_job&quot;&gt;Joe Jobbed&lt;/a&gt;.  Is the spam showing up in your sent items folder?</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.79859-1185086</guid>
		<pubDate>Mon, 31 Dec 2007 16:34:34 -0800</pubDate>
		<dc:creator>krisjohn</dc:creator>
	</item><item>
		<title>By: deadmessenger</title>
		<link>http://ask.metafilter.com/79859/Help-me-snatch-a-hackerspammer#1185088</link>	
		<description>It&apos;s unlikely to be really coming from your hotmail account.  It&apos;s called spoofing, and it&apos;s really common.    I did enterprise email support for many years, and here&apos;s a little primer that I&apos;ve shared with the users over the years who&apos;ve called me about this very issue.  &lt;br&gt;
&lt;br&gt;
&lt;em&gt;SMTP, or Simple Message Transfer Protocol, is the protocol used to transmit email between servers on the Internet.    Unfortunately, the designers of the SMTP protocol did not anticipate the commercialization of the Internet, and the designed SMTP to be accessible, rather than secure.  One of the consequences of this is the fact that SMTP is unauthenticated, meaning that anyone can send email &quot;as&quot; anyone else, and it is trivial for someone to falsify (or &quot;spoof&quot;) the sender of an email.  Furthermore, it is possible (and preferable) for someone to do so without any access whatsoever to the apparent (fake) sender&apos;s email account.   &lt;br&gt;
&lt;br&gt;
What this means:  No, you&apos;ve not been hacked, nor have our servers been hacked.   It is extremely unlikely that any (my employer&apos;s name) facilities have been used to send this email, and for that reason, we are powerless to stop or mitigate this.    Sorry.    Please let me know if I need to explain further.&lt;br&gt;
&lt;/em&gt;</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.79859-1185088</guid>
		<pubDate>Mon, 31 Dec 2007 16:38:36 -0800</pubDate>
		<dc:creator>deadmessenger</dc:creator>
	</item><item>
		<title>By: deadmessenger</title>
		<link>http://ask.metafilter.com/79859/Help-me-snatch-a-hackerspammer#1185089</link>	
		<description>Hit &quot;post comment&quot; too soon on my last response.   Usually the &quot;explain further&quot; would take the form of me visiting the complaining user&apos;s desk and using a simple telnet session to send an email to their account from some really unlikely email address: elvis@graceland.com, santa@northpole.gov were a couple of my favorites.   Then, once the message was received a few milliseconds later, I would be able to show them what SMTP headers look like.  That demonstration usually drove it home just how easy it was to fake an email, and gave the user a little more insight into spammer tactics.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.79859-1185089</guid>
		<pubDate>Mon, 31 Dec 2007 16:47:44 -0800</pubDate>
		<dc:creator>deadmessenger</dc:creator>
	</item><item>
		<title>By: snsranch</title>
		<link>http://ask.metafilter.com/79859/Help-me-snatch-a-hackerspammer#1185090</link>	
		<description>Well, yes, they are showing up in my sent items and I&apos;ve had MANY delivery failures listed.&lt;br&gt;
&lt;br&gt;
This is the last message that was sent.  Note:  the listed http has been different in different messages.&lt;br&gt;
&lt;br&gt;
snsranch@hotmail.com wrote:&lt;br&gt;
&lt;br&gt;
    try my own film&lt;br&gt;
    I&apos;ve been browsed a selfmade website for uploading good pics and movies.There are my video contents on my new blog, Just for fun. http://blog.goldwindos2000.com/blog.html</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.79859-1185090</guid>
		<pubDate>Mon, 31 Dec 2007 16:51:29 -0800</pubDate>
		<dc:creator>snsranch</dc:creator>
	</item><item>
		<title>By: aubilenon</title>
		<link>http://ask.metafilter.com/79859/Help-me-snatch-a-hackerspammer#1185091</link>	
		<description>Have you told Outlook Express you Hotmail password?  Maybe someone&apos;s hacked your computer and is using some kind of automation to send messages?&lt;br&gt;
&lt;br&gt;
Have you tried contacting hotmail support?&lt;br&gt;
&lt;br&gt;
At least they aren&apos;t posting &quot;your&quot; film to Projects!</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.79859-1185091</guid>
		<pubDate>Mon, 31 Dec 2007 16:55:17 -0800</pubDate>
		<dc:creator>aubilenon</dc:creator>
	</item><item>
		<title>By: snsranch</title>
		<link>http://ask.metafilter.com/79859/Help-me-snatch-a-hackerspammer#1185094</link>	
		<description>No I don&apos;t use Outlook and haven&apos;t contacted support.  There are no alternate addies listed.  I guess I should just contact support.  &lt;br&gt;
&lt;br&gt;
Weird stuff.  Let&apos;s see what happens.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.79859-1185094</guid>
		<pubDate>Mon, 31 Dec 2007 17:03:11 -0800</pubDate>
		<dc:creator>snsranch</dc:creator>
	</item><item>
		<title>By: Pants!</title>
		<link>http://ask.metafilter.com/79859/Help-me-snatch-a-hackerspammer#1185095</link>	
		<description>Is the IP address on the sent items spam your IP address?</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.79859-1185095</guid>
		<pubDate>Mon, 31 Dec 2007 17:04:43 -0800</pubDate>
		<dc:creator>Pants!</dc:creator>
	</item><item>
		<title>By: deadmessenger</title>
		<link>http://ask.metafilter.com/79859/Help-me-snatch-a-hackerspammer#1185103</link>	
		<description>The fact that the msgs are in your sent mail changes matters entirely.  My first guess after hearing that is that your account has been compromised in some way, likely through some piece of malware on your machine.  The delivery failures don&apos;t matter - they&apos;re also a symptom of spoofing.   &lt;br&gt;
&lt;br&gt;
You may want to change your Hotmail password from another machine.  One possibility that I&apos;m thinking of here is that you have a keylogger on your box - if your machine is infected, it&apos;s possible that you may be giving your new password away when you change it or log in from that machine.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.79859-1185103</guid>
		<pubDate>Mon, 31 Dec 2007 17:21:51 -0800</pubDate>
		<dc:creator>deadmessenger</dc:creator>
	</item><item>
		<title>By: flug</title>
		<link>http://ask.metafilter.com/79859/Help-me-snatch-a-hackerspammer#1185105</link>	
		<description>As Pants! suggests, you could probably tell quite a bit by carefully examining the headers of the &quot;delivery failure&quot; messages.  There you can find the originating IP address and other interesting info.  Look up IP addresses using something like &lt;a href=&quot;http://www.arin.net/whois/&quot;&gt;this web site&lt;/a&gt; to find the name/owner o the IP addresses you find.&lt;br&gt;
&lt;br&gt;
By way of comparison, send yourself an email (or several over a period of time--most large ISPs use different email servers at different times for a variety of reasons) via your hotmail account, examine the headers of that, look up the IP addresses you find.&lt;br&gt;
&lt;br&gt;
As suggested above, what you will likely find is that the spam did not actually originate from your account at hotmail.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.79859-1185105</guid>
		<pubDate>Mon, 31 Dec 2007 17:25:49 -0800</pubDate>
		<dc:creator>flug</dc:creator>
	</item><item>
		<title>By: snsranch</title>
		<link>http://ask.metafilter.com/79859/Help-me-snatch-a-hackerspammer#1185107</link>	
		<description>Ok, checking IPs.&lt;br&gt;
&lt;br&gt;
Thanks a lot for the help guys!  I really appreciate it.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.79859-1185107</guid>
		<pubDate>Mon, 31 Dec 2007 17:34:50 -0800</pubDate>
		<dc:creator>snsranch</dc:creator>
	</item><item>
		<title>By: flabdablet</title>
		<link>http://ask.metafilter.com/79859/Help-me-snatch-a-hackerspammer#1185224</link>	
		<description>If you have a keylogger installed, you might need to go to fairly extreme lengths to remove it - those things are designed to be hard to find, and often use rootkit techniques to hide themselves.  Doing a malware scan from outside Windows is your best bet.  I like the &lt;a href=&quot;http://trinityhome.org/Home/index.php?wpid=1&amp;front_id=12&quot;&gt;Trinity Rescue Kit&lt;/a&gt; for this.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.79859-1185224</guid>
		<pubDate>Mon, 31 Dec 2007 21:13:38 -0800</pubDate>
		<dc:creator>flabdablet</dc:creator>
	</item><item>
		<title>By: InnocentBystander</title>
		<link>http://ask.metafilter.com/79859/Help-me-snatch-a-hackerspammer#1185628</link>	
		<description>[IB&apos;s wife]&lt;br&gt;
&lt;br&gt;
When i had this happen, it was because an ex was keylogging me.  It was just lovely, because he was sending obscene messages to my entire family, as well as messages telling my new boyfriend that I was a fat bitch and would hurt him terribly.  If your messages are more general spam, I&apos;d imagine it&apos;s some sort of malware from a spammer.  But if they seem at ALL targeted, suspect someone in your life.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2008:site.79859-1185628</guid>
		<pubDate>Tue, 01 Jan 2008 15:59:35 -0800</pubDate>
		<dc:creator>InnocentBystander</dc:creator>
	</item>
	</channel>
</rss>
