Please help me decipher this header - I'm desperate!


 
Thread Tools Search this Thread
Top Forums UNIX for Dummies Questions & Answers Please help me decipher this header - I'm desperate!
# 1  
Old 02-07-2005
Please help me decipher this header - I'm desperate!

I've got a really weird situation here.... the same IP address keeps popping up in porn spam that I have rec'd in 2 different email accts. It looks to me like it's coming from UC Davis, and I suspect someone there, so I am hoping you all can verify the same thing before I call the person on this spamming.... If in fact you guys come up with the same info I do, then can anyone tell me, aside from this person logging into the culprit Yahoo accounts (the ones I have denoted with ~~~~~~ in the copy of the headers), and there are 2 different Yahoo accts, if there is any other way for the spam to be sent from UCD to me? Can it somehow be bounced off UCD server but not really originate there? I just want to make sure I cover everything before I confront this person, & I just keep thinking, he must have 2 separate Yahoo accounts that he has kept secret & sends me this crap from the University for whatever creepy reasons". Can I be wrong somehow or does this all sound about right?

This first header is from my hotmail acct, again with the ISP 169.237.221.161, but what's all the weird stuff after X-Message info?? From what I've read on the internet, this looks like a fraudulent email somehow, but... is it still originating at the university?



From*:*
~~~~~~@yahoo.com>
Sent*:*
Sunday,*February*6,*2005*8:31*PM
To*:*
**ME**@hotmail.com

Subject*:*
H@me l^@ns 5%

Inbox

Attachment*:**
5_5.jpg*(0.07 MB), 5_10.jpg*(0.08 MB), 5_11.jpg*(0.08 MB), 5_14.jpg*(0.07 MB), roxanne126.jpg*(0.29 MB)

MIME-Version: 1.0
Received: from web90008.mail.scd.yahoo.com ([66.218.94.66]) by mc1-f16.hotmail.com with Microsoft SMTPSVC(6.0.3790.211); Sun, 6 Feb 2005 20:31:56 -0800
Received: (qmail 77320 invoked by uid 60001); 7 Feb 2005 04:31:56 -0000
Received: from [169.237.221.161] by web90008.mail.scd.yahoo.com via HTTP; Sun, 06 Feb 2005 20:31:55 PST
X-Message-Info: JGTYoYF78jESyuYhQdPiJ/0TCP4/vMP5OAZwQP/VhFM=
Comment: DomainKeys? See http://antispam.yahoo.com/domainkeys
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=s1024; d=yahoo.com; b=rXgkPbY4drIvpBxlNAYHQeu+tsNBOJMQxEEcQcNM6DzismhOJGcUDzkFefFncx2CxgBHNW3XwORycm5eNqZFn9dJj5rHO0U+t6 HOYHpbmYfJO0gPUglhxfgS9907Po1CFc7BpRhrcJtNncI92NRllab/C40edJFC0H3BaXrRCnI= ;
Return-Path: ~~~~~~@yahoo.com
X-OriginalArrivalTime: 07 Feb 2005 04:31:56.0191 (UTC) FILETIME=[F4A06AF0:01C50CCD]



This second email header is from my Excite email acct, and this time the sender is different (still Yahoo though) but the IP address hasn't changed. University again? What do you guys think?



Return-Path:**
<~~~~~~@yahoo.com>

Delivered-To:**
**ME**@xprdmailbe.nwk.excite.com

Received:**
(qmail 28808 invoked from network); 18 Dec 2004 00:40:09 -0000
Received:**
from unknown (HELO xprdmx8.nwk.excite.com) ([10.50.30.29]) (envelope-sender <~~~~~~@yahoo.com>)
by 0 (qmail-ldap-1.03) with SMTP
for <**ME**@xprdmailbe.nwk.excite.com>; 18 Dec 2004 00:40:09 -0000
Return-Path:**
<~~~~~~@yahoo.com>
Received:**
from web80904.mail.scd.yahoo.com (web80904.mail.scd.yahoo.com [66.218.95.67])
by xprdmx8.nwk.excite.com (Postfix) with SMTP id 87A9B29DDA
For <**ME**.com>; Fri, 17 Dec 2004 19:40:03 -0500 (EST)
Received:**
(qmail 1283 invoked by uid 60001); 18 Dec 2004 00:40:08 -0000
Comment:**
DomainKeys? See http://antispam.yahoo.com/domainkeys
DomainKey-Signature:**
a=rsa-sha1; q=dns; c=nofws;
s=s1024; d=yahoo.com;
b=ikhwTrBLI/vyaDrTOy3fCUGC/0ML49mVgKnWMr33bS9Q/XJ1O2izYem2kvc0MwCp+FYtHhXXPhbuiqXT1olbAOc0RK9aZTqXLQz4LpOHh5Zladaqke8d4Ar46K5RDEi726HwfI7CKTAk9ibZL ug6TGv4ya8tW52jYNooyl87xbc= ;
Message-ID:**
<20041218004008.1281.qmail@web80904.mail.scd.yahoo.com>
Received:**
from [169.237.221.161] by web80904.mail.scd.yahoo.com via HTTP; Fri, 17 Dec 2004 16:40:07 PST
Date:**
Fri, 17 Dec 2004 16:40:07 -0800 (PST)
From:**
<~~~~~~@yahoo.com>
Subject:**
Hi Hun
To:**
**ME**@excite.com
 
Login or Register to Ask a Question

Previous Thread | Next Thread

9 More Discussions You Might Find Interesting

1. Shell Programming and Scripting

decipher shell commands

Hi Guys, I am busy trying to re-write a shell script that was written way back. I need help with these codes: # Process switches if ; then echo "usage : process <optional instance>" exit 99 fi What does the above code mean? What does these $? -gt 1 mean? Then I have... (3 Replies)
Discussion started by: Phuti
3 Replies

2. SuSE

can you decipher this script ?

ssh-add -t 30 >/dev/null 2>&1 LOGNAME=`whoami` cp $HOME/.ssh/known_hosts $HOME/.ssh/known_hosts.org grep -v localhost $HOME/.ssh/known_hosts.org > $HOME/.ssh/known_hosts ssh -1 -f -l $LOGNAME -o "ForwardX11 yes" -o "StrictHostKeyChecking no" -L 6003:195.244.210.107:2222 ext-proxy-2 sleep 5... (7 Replies)
Discussion started by: llcooljatt
7 Replies

3. Shell Programming and Scripting

csh desperate help...

Hi guys, I am really newbie of csh and I am stuck with a script. Basically what I want to do is assign to a variable (array) the output of "ls". Then look at this array and if there is the word "my_file", delete it from the array and echo the new array. Moreover, I would like to have that... (8 Replies)
Discussion started by: Mandrake83
8 Replies

4. Shell Programming and Scripting

Can you decipher this script ?

ssh-add -t 30 >/dev/null 2>&1 LOGNAME=`whoami` cp $HOME/.ssh/known_hosts $HOME/.ssh/known_hosts.org grep -v localhost $HOME/.ssh/known_hosts.org > $HOME/.ssh/known_hosts ssh -1 -f -l $LOGNAME -o "ForwardX11 yes" -o "StrictHostKeyChecking no" -L 6003:1.1.1.1:2222 ext-proxy-2 sleep 5... (1 Reply)
Discussion started by: llcooljatt
1 Replies

5. UNIX for Advanced & Expert Users

ssh decipher a tunnel

Two question here, but it's only one on the protocol point of view. If two persons use the same key to connect to a SSH server is there a risk they can decipher the other tunnel. In other terms is that less safe than if they have two separate keys. Same question if two persons use the same user... (2 Replies)
Discussion started by: moi
2 Replies

6. Shell Programming and Scripting

Decipher Script

Hi Guys, I am running solaris and I need help in deciphering the following commands: dir_t1=`echo $0|nawk -F'/' '{print NF}'` dir_t2=`expr $dir_t1- 1` dir_t3=`echo $0|cut -d'/' -f1-$dir_t2` export dir_t2 What will be the value for dir_t3? Please help !!!!!!!!!!!!!!! (5 Replies)
Discussion started by: Phuti
5 Replies

7. HP-UX

help me decipher how much memory on my box

hi, if I do top, I get Memory: 19277012K (5868296K) real, 33860312K (11294208K) virtual, 795392K free If I do swapinfo -tm I get: % swapinfo -tm Mb Mb Mb PCT TYPE AVAIL USED FREE USED dev 16384 0 16383 0% dev ... (3 Replies)
Discussion started by: JamesByars
3 Replies

8. Cybersecurity

How to decipher tcpdump file

Hi, I am stuck with a tricky situation in which one of my applications is flooding the network with UDP messages. The architecture of the application is not supposed to do so. Neither is there any place where the application will go into an infinite loop sending UDP messages over the network. To... (3 Replies)
Discussion started by: diganta
3 Replies

9. UNIX for Dummies Questions & Answers

I am confused and desperate

Hello, For a time now I have this problem which I cannot solve and this bothers me cause it seems so simple. I have to change an existing (ftp only)user to create a timeslot for this user. (e.g. he can only login between 8 and 10 PM). Facts: - I can only use a terminal client (no gui) -... (1 Reply)
Discussion started by: derk
1 Replies
Login or Register to Ask a Question