Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations biv343 on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

E-Mail Tracking Help Please 1

Status
Not open for further replies.

deklin

IS-IT--Management
Nov 6, 2002
157
US
Hi,

I am having a major problem. Someone has been sending one of my employees inapproprate emails and intentionally including threats and virus' in them. I know the the person is traveling around and using free "hot spots" (Starbucks, Airports, Etc.) to do this. How do I track down the individual?

Thanks a lot

Deklin [yinyang]

"What goes up must come down. Ask any system administrator."
 
Keep the headers and compare them after a while, some may contain identical parts.
If he/she is using the same mailaddress, send a message from an offsite account, hotmail or so, with a friendly message abot some info, as if you where sending it to John Aplleby or so. Basically, it would 'look' to him as if where addressing the wrong person, and if you are in luck, he will reply to that. Whatever you send, do NOT mention the 'attacks' or so, play the 'stupid' one who just send an email to the wrong person.

If any repetitive parts are found in the headers, block it.

Marc
If 'something' 'somewhere' gives 'some' error, expect random guesses or no replies at all. Please specify details.
Free Tip: The F1 Key does NOT destroy your PC!
How Do You Get Great Answers To my Tek-Tips Questions?
See faq222-2244
 
can you post the headers here? i will take a look at them and see what i can tell you.
 
Do email headers contain any type of definitive tracking information. For example the originatin mac address of the sender?

Deklin [yinyang]

"What goes up must come down. Ask any system administrator."
 
yes they show the complete route the email took from point A to point B. however, if the person sending them is savvy they can bugger up some of the header info.

just looking at them doesn't do much good. the application of some investigative software/methods tell more of the story.
 
how would i go about viewing the complete header information? sometimes it doesnt show up by the default view

Deklin [yinyang]

"What goes up must come down. Ask any system administrator."
 
if you are using Outlook (XP or 2000)

right click on the message in the INBOX
click on OPTIONS
look at the bottom of the popup & you will see INTERNET HEADERS

this is the info you need
 
Can the 'out of office notification' in outlook 2003 be used without exchange server?
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top