GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   How to stop kiddy porn e-mails, wanna-be stalkers, and attacks from mutants (https://gfy.com/showthread.php?t=100397)

heqdvd 01-16-2003 09:37 AM

How to stop trash e-mails, wanna-be stalkers, and attacks from mutants
 
How to stop trash e-mails, wanna-be stalkers, and attacks from mutants

Sure, we all get tons of Klez-H type auto, generated e-mail viruses.
But say you have some stalker that is so frustrated by their lack of importance, creative impotence and total rejection by society that they won?t quit. There is an answer.

Trace the e-mail. Contact the e-mail SOURCE, repeatedly and as a doggedly as the malformed Internet ?user? does to you. Then set up filters to simply erase the next similar type of e-mail from coming in.

Here?s a very silly, juvenile and jealous repeated e-mail I kept getting (though the From: line changed).
-----------------------------------------------------------------------
From: dillonthomas77 [[email protected]]
Sent: Wed 1/15/03 8:06 PM
To: [email protected]

Hi,greggdilorenzo,some questions
---------------------------------------------------------------------

The e-mail has no text in it, of course, but my firewall stripped the malicious attachment immediately and warned me?

RULE ONE ? Set you firewall or E-mail client to ?quarantine? all attachments to a closed area of your hard disk. This is not hard at all, depending on the actual program or client it should take 2-3 steps.

RULE TWO ? Right click the actual e-mail in your e-mail (using outlook) and choose ?options?. Copy all the text to a text processor:

Return-Path: <[email protected]>
Received: from au00.com ([210.18.218.2])
by lsh100.siteprotect.com (8.9.3/8.9.3) with SMTP id TAA27859
for <[email protected]>; Wed, 15 Jan 2003 19:05:35 -0600
Date: Wed, 15 Jan 2003 19:05:35 -0600
Message-Id: <[email protected]>
Received: (qmail 26490 invoked from network); 16 Jan 2003 01:01:15 -0000
Received: from tory-177.gateway.to.the.fraser.coast.au00.com (HELO Iamoozahd) (210.18.218.177)
by sarah.maryboroughqld.com with SMTP; 16 Jan 2003 01:01:15 -0000
From: dillonthomas77 <[email protected]>
To: [email protected]
Subject: Hi,greggdilorenzo,some questions
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary=E9MZ80N4f3832z9RP

Ay yes, this [email protected]? has been stupidly diligent lately, like a ?VILLAGE? idiot? I recognized this name.

RULE THREE ? Right click in the message body and do ?view source? Copy this text as well?
HTML><HEAD></HEAD><BODY>
iframe src=cid:RC9YL7j5U4H5MUjY50 height=0 width=0>
iframe>
FONT></FONT></BODY></HTML>
[altered code because of limitations of PHP format here]

Ah? I won?t get into hex codes here, but this type of approach betrays the ignorance of the sender very clearly. The fact of the matter is that if step one isn?t followed, problems arise from the attachment here.


RULE FOUR - Go to a e-mail tracking service, such as http://spamcop.net, sign up for a free account and then paste all of the above info into the submit box. Press enter, and wait for the program to work.

Possible spammer: 210.18.218.2
210.18.218.2 is not an MX for au00.com
host au00.com (checking ip) = 210.18.218.12
210.18.218.2 is not an MX for au00.com
ips are close enough
Taking name from IP...
host 210.18.218.2 (getting name) no name
Received line accepted

Received: (qmail 26490 invoked from network); 16 Jan 2003 01:01:15 -0000
no ip found in received line
Ignored

Received: from tory-177.gateway.to.the.fraser.coast.au00.com (HELO Iamoozahd) (210.18.218.177) by sarah.maryboroughqld.com with SMTP; 16 Jan 2003 01:01:15 -0000
host 210.18.218.2 (getting name) no name
210.18.218.2 not listed in opm.blitzed.org
Possible spammer: 210.18.218.177
210.18.218.177 is not an MX for tory-177.gateway.to.the.fraser.coast.au00.com
host tory-177.gateway.to.the.fraser.coast.au00.com (checking ip) = 210.18.218.177
Taking name from IP...
host 210.18.218.177 (getting name) no name
Chain test:sarah.maryboroughqld.com =? au00.com
host au00.com (checking ip) = 210.18.218.12
210.18.218.12 is an MX for maryboroughqld.com
210.18.218.12 is mx
sarah.maryboroughqld.com and au00.com have close IP addresses - chain verified
Possible relay: 210.18.218.2
210.18.218.2 not listed in relays.ordb.org.
210.18.218.2 has already been sent to relay testers
Received line accepted
Tracking message source: 210.18.218.177:
Routing details for 210.18.218.177
[refresh/show] Cached whois for 210.18.218.177 : [email protected]
Using last resort contacts [email protected]
Whois found [email protected]
ISP has already cancelled the account used to send this spam. ISP resolved this issue sometime after Thu Jan 16 01:01:15 2003 GMT Wednesday, January 15, 2003 8:01:15 PM -0500
210.18.218.177 not listed in formmail.relays.monkeys.com
210.18.218.177 not listed in opm.blitzed.org
210.18.218.177 not listed in relays.ordb.org.
210.18.218.177 not listed in query.bondedsender.org
Finding IP block owner:
Routing details for 210.18.218.177
[refresh/show] Cached whois for 210.18.218.177 : [email protected]
Using last resort contacts [email protected]

RULE FIVE: Make sure it IS SPAM, and then take the appropriate actions, like contacting the administrator.
If you are polite, they usually respond, though it might take a few tries!

You can see they cancelled that user?s account. It worked. This doesn?t mean the mutant won?t just jump to another server of mailer system. But he/she had to actually ?work? for a second, thus our mission is successful.

I feel 1,000,000 issues would be resolved if people simply stated their real names and addressed REAL issues they have with members of this planet earth. But this is an idealist dream that never will be realized.


In the mean time ? TURN OFF THE SPAMMERS E-MAIL ACCOUNTS?. Contact the administrators!


Peace and love from NYC.
http://heqdvd.com
(newly updated)

Socks 01-16-2003 09:38 AM

I think he just wants kiddy porn. :winkwink:

heqdvd 01-16-2003 09:41 AM

Typical response from mutants like those described above. Funny how all the e-mails come from .au or .ca!

I see your validity by all the great work you've done in your sig sites...
"Although our website is geared towards surfers looking to buy accounts, we feel that ASS can be just as much of a resource to webmasters as it is for consumers."

Socks 01-16-2003 09:46 AM

What the fuck are you talking about? It was an inside joke. Stay outside.

Socks 01-16-2003 09:46 AM

And what exactly are you saying about Canada? Expand. Please.

heqdvd 01-16-2003 09:48 AM

here:

http://www.gofuckyourself.com/showth...35#post1257635

Socks 01-16-2003 09:49 AM

How slow are you? It was the same kind of thread, and I saw it when it was posted, so I posted the same response... This time with a wink. Relaaax.

heqdvd 01-16-2003 09:50 AM

Sure -

I'll relax when when I stop getting these kinds of mails...


But you marketing is original, at least.

Socks 01-16-2003 09:54 AM

I thought you liked them... I'll stop. :/

heqdvd 01-17-2003 09:03 PM

now i'm getting hacked by the russian feds!


I got the Russian Federation trying to hack me now!

Feel sort of good...


NETWORK: 217.107.214.246 [512]
inetnum: 217.107.214.0 - 217.107.215.255
netname: CHARACTER
descr: CHARACTER NETWORK
descr: Russian Federation, Moscow
descr: N. Bashilovka, 6
country: RU
admin-c: CL578-RIPE
tech-c: CL578-RIPE
status: ASSIGNED PA
notify: [email protected]
notify: [email protected]
mnt-by: AS8342-MNT
changed: [email protected] 20020628
changed: [email protected] 20020719
source: RIPE


All times are GMT -7. The time now is 03:16 AM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123