Spam message with fake "From" imposing list owner to list owners

Savvas Radevic vicedar at gmail.com
Fri Feb 13 15:51:14 GMT 2009


I would like to bring to your attention a spam message you might
receive if you're the owner of a mailing list.
Namely, a spam message is floating around, faking the "From" header,
as if it was sent from the "ubuntu-cy-owner" email (in my case) to the
"ubuntu-cy-owner".

I was personally puzzled when I saw that message, but when I checked
the folder with the spam messages, it was clear that there was a spam
message imposing to be sent from "ubuntu-cy-owner".

The mailing list owners will receive a) the spam message and b) an
auto-response email such as:
[Quote]
Auto-response for your message to the "Ubuntu-cy" mailing list
Your email has been sent to the administrators, you will be contacted
if necessary.

The Cyprus Ubuntu LoCo Team
[End of quote]

The interesting part of the email headers is attached:
[Quote]
Received: from localhost ([127.0.0.1] helo=chlorine.canonical.com)
	by chlorine.canonical.com with esmtp (Exim 4.60)
	(envelope-from <mailman-bounces at lists.ubuntu.com>)
	id 1LXxwK-0004vj-II; Fri, 13 Feb 2009 13:18:44 +0000
Received: from [41.246.98.26] (helo=rrba-ip-pcache-5-vif0.telkom-ipnet.co.za)
	by chlorine.canonical.com with esmtp (Exim 4.60)
	(envelope-from <ubuntu-cy-owner at lists.ubuntu.com>)
	id 1LXxwG-0004qK-HM
	for ubuntu-cy-owner at lists.ubuntu.com; Fri, 13 Feb 2009 13:18:41 +0000
To: <ubuntu-cy-owner at lists.ubuntu.com>
Subject: Big, rock hard meat
From: <ubuntu-cy-owner at lists.ubuntu.com>
[End of quote]

P.S. I thought it would be nice to inform other people about this, so
they won't get puzzled. :)



More information about the loco-contacts mailing list