Wednesday, July 23, 2003

Now we're being spammed by morons!!

OMG!!! I'm being spammed by an idiot now. While it does fall under the "forged header" category (which means I can sue for $$$), he's not selling anything (which means I can't sue, I think).

Anyways, following is the header and body of the message after it passed through SpamAssassin. The message purported to be from rickisok@bahn.de but actually originated from a originated from an IP address belonging to the Department of Social Security of UK!!! (Methinks that someone is testing a Jeem or SoBig worm-compromised system within the GB.)

For those of you new to reading message headers, you read the "Received" lines from the bottom up (for chronological order). I can vouch for anything generated by cox.net as being legit.

  

Return-Path:
Received: from pop.cox.east by localhost with POP3 (fetchmail-6.2.1) for joat@localhost (single-drop); Wed, 23 Jul 2003 06:30:18 -0400 (EDT)
Received: from host-148-244-152-186.block.alestra.net.mx ([200.76.178.243]) by lakemtai04.cox.net (InterMail vM.5.01.04.05 201-253-122-122-105-20011231) with SMTP id ; Wed, 23 Jul 2003 06:24:26 -0400
Received: from vi3m.4fyzhbh.net [51.41.95.3] by host-148-244-152-186.block.alestra.net.mx id for ; Wed, 23 Jul 2003 15:09:43 +0200
Message-ID:
From: rickisok@bahn.de
To: xxxx.xxxx@cox.net, krarge@cox.net, krastonscott@cox.net, kratten@cox.net, kraut1-9@cox.net, krawietz@cox.net, kraynekg@cox.net
Subject: *****SPAM***** Need Dimensional Warp Generator ahd
Date: Wed, 23 Jul 03 15:09:43 GMT
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.00.2919.6700
MIME-Version: 1.0
Content-Type: text/plain
X-Spam-Status: Yes, hits=4.0 required=4.0 tests=MISSING_MIMEOLE,NO_REAL_NAME,SPAM_PHRASE_02_03, SUPERLONG_LINE,SUSPICIOUS_RECIPS,USER_AGENT_OE, VERY_SUSP_RECIPS version=2.44
X-Spam-Flag: YES
X-Spam-Level: ****
X-Spam-Checker-Version: SpamAssassin 2.44 (1.115.2.24-2003-01-30-exp)
X-Spam-Prev-Content-Type: multipart/alternative; boundary="E.3.EAD.3C"
X-Evolution-Source: imap://joat@127.0.0.1/

SPAM: