Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > Software - Troubleshooting and Discussion > Applications > fake messages from "Mail Delivery Subsystem"

fake messages from "Mail Delivery Subsystem"
Thread Tools
Mac Elite
Join Date: Jan 2000
Location: Columbus, OH
Status: Offline
Reply With Quote
Jul 18, 2010, 07:52 AM
 
I've just recently started getting a lot of bogus messages similar to this:

From: Mail Delivery Subsystem <MAILER-DAEMON@ogham.futhark.ch>
Subject: Returned mail: see transcript for details
Date: July 18, 2010 7:40:03 AM EDT
To: xxxxxxxxxxxx <xxxxxxx@xxxx.com>
The original message was received at Sun, 18 Jul 2010 11:21:35 GMT
from [41.249.29.114]

----- The following addresses had permanent fatal errors -----
<biggerd@futhark.ch>
(reason: 550 5.1.1 User unknown)

----- Transcript of session follows -----
550 5.1.1 <biggerd@futhark.ch>... User unknown
Reporting-MTA: dns; ogham.futhark.ch
Arrival-Date: Sun, 18 Jul 2010 11:21:35 GMT

Final-Recipient: RFC822; biggerd@futhark.ch
X-Actual-Recipient: RFC822; biggerd@ogham.futhark.ch
Action: failed
Status: 5.1.1

--------------------------------------

Now I know this is some kind of scam or social engineering attempt but I don't see how it's supposed to work.

Anybody seen this kind of stuff before?
HyperNova Software, LLC
     
Administrator
Join Date: Apr 2001
Location: San Antonio TX USA
Status: Offline
Reply With Quote
Jul 18, 2010, 08:21 AM
 
Not necessarily a scam. It could be that someone has used your email address in the "from" field for spam. This happens to me on one of my public addresses every now and then. I've wound up either writing a rule to trash "mailer daemon" mail or simply ignoring these replies.
Glenn -----
OTR/L, MOT, Tx
     
Mac Elite
Join Date: Jan 2000
Location: Columbus, OH
Status: Offline
Reply With Quote
Jul 18, 2010, 08:25 AM
 
Originally Posted by ghporter View Post
Not necessarily a scam. It could be that someone has used your email address in the "from" field for spam. This happens to me on one of my public addresses every now and then. I've wound up either writing a rule to trash "mailer daemon" mail or simply ignoring these replies.
Yeah, it's probably somebody using my email address.

I've had the same email address for about 10 years now. I think it's time to start fresh and NEVER post the new address on the Internet. MobileMe lets you set up alias so I could use one of them for those times when places like Amazon.com require an email address. If that alias gets compromised I think you can delete it and create a replacement. Not sure about the MobileMe rules regarding aliases.

Thanks!
HyperNova Software, LLC
     
Posting Junkie
Join Date: Oct 2005
Location: Houston, TX
Status: Offline
Reply With Quote
Jul 18, 2010, 10:49 AM
 
Yea, looks like backscatter to me.
     
Moderator
Join Date: Apr 2005
Location: Cambridge, UK
Status: Offline
Reply With Quote
Jul 18, 2010, 02:25 PM
 
You don't have your own mail server do you?
     
Dedicated MacNNer
Join Date: Mar 2006
Location: Vancouver, BC
Status: Offline
Reply With Quote
Jul 18, 2010, 04:18 PM
 
Originally Posted by msuper69 View Post
MobileMe lets you set up alias so I could use one of them for those times when places like Amazon.com require an email address.
I attend a few tech conferences each year and create an alias for each one. The amount of post conference spam your mandatory badge scanning generates is quite the bore. I simply filter the email into the matching folder and review whenever.
     
Posting Junkie
Join Date: Oct 2005
Location: Houston, TX
Status: Offline
Reply With Quote
Jul 20, 2010, 06:02 PM
 
Was there any javascript in the message? Apparently it's a new attack that Google is now blocking.
     
Mac Elite
Join Date: Jan 2000
Location: Columbus, OH
Status: Offline
Reply With Quote
Jul 20, 2010, 07:07 PM
 
Originally Posted by mduell View Post
Was there any javascript in the message? Apparently it's a new attack that Google is now blocking.
How can I tell? It looks like a plain text message to me.
HyperNova Software, LLC
     
   
Thread Tools
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Top
Privacy Policy
All times are GMT -5. The time now is 08:52 AM.
All contents of these forums © 1995-2011 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.7 © 2000-2011, Jelsoft Enterprises Ltd., Content Relevant URLs by vBSEO 3.3.2