Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

my whole hotmail address book got emailed but I did not do it

Status
Not open for further replies.

airtas

Technical User
Jun 16, 2005
10
US
SO this morning I login to my email and there is a CHINA wholesale electronics email which was sent to everyone in my email but I did not send.....what is going on?
 
Are your Hotmail addresses kept on-line? If so, someone cracked into the server and stole your addresses. Unfortunately, this happens a lot. Hotmail accounts are not the most secure.

Did you keep any info like social security numbers, credit card numbers, or other secure info in there, too? If you did, I would scramble to start canceling cards, letting companies know, etc..


James P. Cottingham
-----------------------------------------
[sup]I'm number 1,229!
I'm number 1,229![/sup]
 
yea the addy book is kept online, I dont have any other info on there except my email.........so these guys know my password?
 
Most likely. :-( It's a good idea to change it now and then.



James P. Cottingham
-----------------------------------------
[sup]I'm number 1,229!
I'm number 1,229![/sup]
 
why would they only mess with one email addy? i have 4 accounts and why would they not hijackit?

is it possible it wasn't really sent directly from my account
 
is it possible it wasn't really sent directly from my account
Yes, if they found a backdoor into the server and was able to crack the address table they could pull those addresses into their server and then send the spam posing as you. For that matter, they could spoof your email server and no one would be the wiser.

i have 4 accounts and why would they not hijackit?
Do all your accounts have the same user name and password? If not, they may have only broken into one account.



James P. Cottingham
-----------------------------------------
[sup]I'm number 1,229!
I'm number 1,229![/sup]
 
Download hijack this from the link below.Please do this. Click here:


to download HijackThis. Click scan and save a logfile, then post it here so
we can take a look at it for you. Don't click fix on anything in hijack this
as most of the files are legitimate.


Member of ASAP Alliance of Security Analysis Professionals

under the name khazars
 
what do u mean spoof the email server
 
what do u mean spoof the email server

Just like they can "pretend" to be you with your email address, they can also "pretend" to be sending from your email server as well. In other words, if they don't do the second, then a scanner could pick up that the email is coming from an invalid mail server, and scrub it. The second method helps get past mostly the automated email scanners.

--

"If to err is human, then I must be some kind of human!" -Me
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top