Someone's sending spam and spoofing my email as the 'From' address. I know they haven't actually hacked my email account because the headers show that the server the mail was sent from wasn't mine, but I'm getting several dozen 'rejected' emails a minute and it's really obnoxious. Is there anything I can do about this other than to wait it out and use mail rules to delete the bounces?
Anything I can do about spam coming from my email address?
That's about all you can do. As you said, they're just spoofing your address, but haven't hacked your account. Since that's the case, tightening security, changinging your password, or loading a patch won't actually solve anything.
If it really bothers you, you can contact the admin of the domain sending you the rejected emails and tell them what's going on. If they've got time and inclination to do so, they may find a way to ignore the incoming email instead of responding to it.
Reply:http://www.spamto.com/
Reply:I think your email *has* been hacked, and/or your computer.
By the sounds of it your email might be being used by a "Zombie Network" to send out spam, that's why the headers show the emails originating from a different server or servers.
Basically, when a hacker wants to set up a "Zombie Network" he does it by first infecting other computers with a virus program designed to record logins and passwords then bypass security firewalls. Each computer infected is then used to spread the program and infect more computers. Once the hacker has infected enough computers he uses the program to direct simultaneous "attacks" on a single server. The hacker can either use these types of attacks to "provide cover" by keeping the server busy (so that they can access its programs/data) or actually crash the server (to kill control/service it provides) by overwhelming it with traffic. The hacker's viral program runs in the background and the infected computers mindlessly carry out the hacker's commands, hence the "zombie" reference.
Your email account could have been comprimised by ANY computer you may have used to check your email... home, laptop, work, public/campus library, or other friend/family computer.
In ANY case, you will most likely need to abandon the email account, save whatever messages and clean attachments (like pics from friends and family) to your computer. If you don't close out the account yourself chances are the account administrator will. The system is probably set up to kill accounts with hundreds of rejects for spamming since this is a clear sign of hacker activity. So, best to backup what you want to keep as soon as possible before you get completely locked out. Be sure to notify the email administrator of the problem so that they know you are not the actual spammer.
The most important thing to do is temporarily disconnect from the net (wireless and hard-line connections) and use an up-to-date security program to scan for viruses, spyware, and other infected files. Make sure your computer(s) are clean and then make sure you set up your security program's firewall before reconnecting to the net. After everything checks out, go ahead an create your new email account, don't do it before scanning or else any viruses you may have will just comprimise the new account as well.
I'd also advise telling all your friends and family to do the same since there is no way of telling whether the infection originated from (or spread to) one of their computers.
My program is set up for max security, to where I have to actually have to click approval for every communication attempt. It's a pain, but at least I can attempt to monitor what my computer "talks" to when I'm connected to the net. I'm a bit paranoid about computer viruses, so that's just the way I do things. You may or may not want to do the same, but you should definately be more careful and use good security programs and anti-viruses.
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment