cancel
Showing results for 
Search instead for 
Did you mean: 

Anyone work this out

N/A

Anyone work this out

Got an email originating from plusnet, as far as I know its spam, dont remember subscribing to anything, at the bottom of the email it has the usual

Quote
This email has been verified as Virus free
Virus Protection and more available at http://www.plus.net



This is the header, for you experts out there lol

Quote
Return-Path: <a4techo14@yahoo.com>
Delivered-To: ro_plu**************net@a**********nse.co.uk
Received: (qmail 60452 invoked from network); 13 Feb 2005 22:04:21 -0000
Received: from unknown (HELO ptb-viruscore02.plus.net) (192.168.71.4)
by ptb-mailstore02.plus.net with SMTP; 13 Feb 2005 22:04:21 -0000
Received: from [192.168.67.1] (helo=ptb-mxcore01.plus.net)by ptb-viruscore02.plus.net with esmtp (Exim 4.43)id 1D0Rqn-00005L-SFfor ********t@*********o.uk; Sun, 13 Feb 2005 22:04:21 +0000
Received: from pih-mxlast01.plus.net ([212.159.6.17])by ptb-mxcore01.plus.net with esmtp (Exim) id 1D0Rs9-0005jB-99 for b********t@angles**********e.co.uk; Sun, 13 Feb 2005 22:05:45 +0000
Received: from [203.177.178.242] (helo=marvin)by pih-mxlast01.plus.net with smtp (Exim 4.30)id 1D0Rqm-0003HJ-JCfor bra*****@angle*******.co.uk; Sun, 13 Feb 2005 22:04:21 +0000
From: "VLA" <a4techo14@yahoo.com>
To: <br*********t@angleseyfi********uk>
Subject: Still skeptical? Here's why you should be!
Mime-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Date: Mon, 14 Feb 2005 06:16:47
X-Virus-Scanned: By PlusNet VirusCORE (v3.01b)

Greetings,

You are at... The Right Place At The Right Time!

Have you ever wondered why some people have been
in the right place at the right time to take
advantage of opportunities that change their life

Well...NOW is YOUR chance. All you have to do is
decide whether you want to seize it, or let it pass
you by.

Developed by the worlds industry leaders and
greatest minds with a proven track record.

This is NOT a fly by night game, here today,
gone tomorrow company.

This is a life-changing, once in a lifetime opportunity...
an opportunity I have waited half my life for!
You Will Be Happy To Know....

If you say yes kindly send your info:

mailto: a4techo14@yahoo.com
Subject: I need to see it first

First Name:
Lasr Name:
Country:

Sincerely,

Vince
a4techo14@yahoo.com
6332-418-2748

====================================================
Note: Kindly put Unsubscribe on the subject if you're not interested.




--
This email has been verified as Virus free
Virus Protection and more available at http://www.plus.net
13 REPLIES
N/A

Anyone work this out

have also worked out that with the bravenet thing in the address, the only way this person got that email address is through my registration at bravenet for a free web counter, does that mean that bravenet are selling on email address's
N/A

Anyone work this out

Hi there,

It didnt originate from Plus Net.
From: "VLA" <a4techo14@yahoo.com>

But was received and processed by their mail servers and virus scanner.

Your theory about Bravenet looks spot on.
N/A

Anyone work this out

Looks like the originating IP is a connection in the Philippines :

Globe Telecom
Pioneer cor Madison Sts, Mandaluyong City
Philippines


Can't see any link between your counter code & the email address. May just be a case of them taking a random word off the page & using that as sendto. I get all sorts of spam at a few of my domains to fred.smith, joe.bloggs etc. where names are just created randomly.

The 6332 part of the phone number is the country code for the Philippines and the number terminates in Cebu City from what I can tell.

Did you use that particular email address when you signed up for the counter?

Fully
N/A

Anyone work this out

Quote
It didnt originate from Plus Net.
From: "VLA" <a4techo14@yahoo.com>


That's the easiest bit to spoof.. you need to look at the originating IP to get more of an idea although that's not always guaranteed Wink

Fully
N/A

Anyone work this out

"does that mean that bravenet are selling on email address's"

It would not surprise me - Bravenet really are the pits AFAIAC. I looked at them as a possibility for a free search engine some time ago and binned the idea after one quick trial - I don't mind having advertsising with a freebie, I expect it, but not the sort of lurid garbage ads that they were feeding me.

Despite being fairly careful when I signed up, I *still* got a whole heap of junk from them that I had *not* subscribed to, which took about six attempts and some very insulting e-mails from me to finally get rid of, and a suspiciously larger than usual amount of that tinned pink stuff arrived at the mail address that I'd given them - not my PlusNet one, of course. I didn't bother checking the headers, but it doesn't take a genius to put two and two together and work out where they came from.

I expect there's some little clause that we missed, hidden in the small print in one millimetre high type, that says "We reserve the right to flog your details to every spammer on the planet".
N/A

Anyone work this out

its the only time i used the bravenet@anglesey..... email address, someone gave me the idea a few weeks ago, where you put the start of the email address as the place you are using, so if you do get spam, you know where its coming from, or at least where your email address is insecure, i guess i learnt now, oh well, thanks for all the info peeps, appreciated
N/A

Anyone work this out

Quote

That's the easiest bit to spoof.. you need to look at the originating IP to get more of an idea although that's not always guaranteed Wink

Fully


Thats fully understood.

I was just wondering how you concluded that it originated from Plus Net.

Yes, whilst the from address is easy to spoof there is no indication that it originated from anyone at Plus Net.

You will have difficulty tracking this one down. But Bravenets actions are suss in this one.
N/A

Anyone work this out

the only reason I thought it was from plusnet was the email virus checker thing at the bottom, bu then again i guess this is just as easy to spoof at the yahoo email addy
N/A

Anyone work this out

That simply shows that it was received by Plus Nets mail servers and scanned by the virus checker.

If you continue to receive spam at this address and if you dont need to monitor it then maybe a forward to blackhole will take care of the problem.

And a swift bol***ing of Bravenet to boot.
N/A

Anyone work this out

yeah I am gonna email bravenet now, thanks for the feedback
csogilvie
Grafter
Posts: 5,852
Registered: 04-04-2007

Anyone work this out

You have virus scanning on, so if the mail is received by the PlusNet servers it will be virus scanned - and that signature added.
mssystems
Rising Star
Posts: 272
Thanks: 35
Fixes: 1
Registered: 10-08-2007

Anyone work this out

Just a couple of small points.

If I were you I would go back and edit your original post munging all the embedded e-mail addys. Having an unadultarated addy on a web page or forum is a great way to attract spam!

The particular mail in question was sent to your domain's backup mail exchanger. This is a common spam tactic as it allows the spammer to bypass relay restrictions and DNS Black lists. Virtually all the spam that hits my own servers comes via mx-last-plus-net.

Whenever you use a 'free' service read the terms and conditions carefully. These services seek to raise revenue wherever they can and that often means selling subscriber details. Alternatively sign up for a disposable hotmail or whatever account and always use that address for free subscriptions. Knowing that the spam originated through bravenet is well and good but it does not prevent your having to receive and process the junk.

HTH
N/A

Anyone work this out

Thanks for the tip, have munged my email address' s not the yahoo one tho, if he sends spam, he deserves some lol....

I did complain to bravenet this morning, and they said I had subscribed to some newsletters when i joined, I know I didnt, I unchecked all the boxes, but what the hey, no harm done, they said they will ensure nothing else gets through, so fingers crossed, and once again, many thanks to all who replied with advice and help