• Security incident: ISF was recently accessed by intruders. Please change your password, and change it anywhere else you used it. Read more

E-mails pretending to be from a contact's Hotmail account

Tanja

Comfortably Numb
Joined
Nov 15, 2003
Messages
3,339
I received a message in my Hotmail inbox yesterday, allegedly from one of my contacts, which was actually a spam message. This contact also has a Hotmail account. I didn't open the message, but from the nonsensical title, as well as from a preview on my phone I could see it was spam, so I deleted it.

Now, does this mean that somebody hijacked her account to send e-mails to her contacts? Or does it mean somebody hijacked my account to send e-mails to me pretending to be from my contacts? Or something else? Could someone kindly explain to me in layman terms how those things happen?
 
I received a message in my Hotmail inbox yesterday, allegedly from one of my contacts, which was actually a spam message. This contact also has a Hotmail account. I didn't open the message, but from the nonsensical title, as well as from a preview on my phone I could see it was spam, so I deleted it.

Now, does this mean that somebody hijacked her account to send e-mails to her contacts? Or does it mean somebody hijacked my account to send e-mails to me pretending to be from my contacts? Or something else? Could someone kindly explain to me in layman terms how those things happen?
I had the same thing happen except all my contacts received spam emails from my Hotmail account. My conclusion was that my password (which wasn't a very strong one) was hacked and the emails sent. I subsequently changed my password to a stronger one, gave my PC a thorough virus check and it hasn't happened again.

Hope that helps
 
Your contact could have had their account compromised and used for spam or a spammer might have a mechanism for spoofing the email address of one of your contacts.
 
Your contact could have had their account compromised and used for spam or a spammer might have a mechanism for spoofing the email address of one of your contacts.

Is there any chance you could explain to me in not-very-technical words how the latter works? I've e-mailed my friend to tell her I got a spam message from her, but if the latter happened than it never had anything to do with her actual account, or did it? :confused:
 
The "from" address in an e-mail is basically no different from the return address on an envelope; it's written by the sender and there's nothing to prevent the sender from putting false information there.

Spammers and malware writers harvest e-mail addresses from the Web for use for both targets and as senders. They fake the sender so it's harder to detect spam, and in some cases to make the target think it's a legitimate e-mail.

That said, it is hard to tell whether the message was because your contact was compromised, or because the mail contained a fake "from" address. If you have the original e-mail, us geeks can get a good idea by inspecting the raw message ("View Source", hidden in various places depending on the e-mail program or web mail you use).
 
THank you all for your answers. I am still very confused about this.

1. If the e-mail did not actually come from her e-mail address, i.e. if someone didn't actually login as her to send those e-mails, how does the spammer know that I am in her contact list, or that she is in my contact list?

2. I never actually opened the message, fearing that it might contain some kind of virus. If I just open the message so I can view source, without clicking on any links etc in it, can anything bad happen?
 
THank you all for your answers. I am still very confused about this.

1. If the e-mail did not actually come from her e-mail address, i.e. if someone didn't actually login as her to send those e-mails, how does the spammer know that I am in her contact list, or that she is in my contact list?
They don't, necessarily. They may have harvested your e-mail address and hers from the same place, e.g. a web page (or Facebook, which has had a number of high-profile issues lately). Or they just got her contact list somehow, without actually taking over her account.

2. I never actually opened the message, fearing that it might contain some kind of virus. If I just open the message so I can view source, without clicking on any links etc in it, can anything bad happen?
Possibly. Most e-mail clients should be secure, as long as you keep them up to date.

However, unless you have a real need to determine if the mail was sent from her account, or from elsewhere, don't bother. A better way of determining if her account was compromised: did all or most of her contacts get spam from her?
 
Thanks for the clarification. Yes, we are friends on Facebook as well, so that is a possibility. I asked her if anyone else got such messages, but she hasn't replied yet.

I wanted to open the message and view the source code more out of curiosity, than anything else. I guess I can restrain myself from doing so. :)
 
Thanks for the clarification. Yes, we are friends on Facebook as well, so that is a possibility. I asked her if anyone else got such messages, but she hasn't replied yet.

I wanted to open the message and view the source code more out of curiosity, than anything else. I guess I can restrain myself from doing so. :)

Try it for a different (valid message). Here's an example, sent to me from Dell Canada. The Received lines are what can be used to guess at the validity of a message, as they are added by each computer that the message passes through enroute to you. If the first few lines don't match the purported source, it's probably faked. Note that for this (valid) case, Google mail (mx.google.com) received the message from dellcanada.outbound.ed10.com, which matches the expected origin.

Code:
Delivered-To: [i]redacted[/i]
Received: by 10.204.84.104 with SMTP id i40cs73367bkl;
        Fri, 20 Aug 2010 07:18:23 -0700 (PDT)
Received: by 10.114.208.20 with SMTP id f20mr1581003wag.69.1282313902308;
        Fri, 20 Aug 2010 07:18:22 -0700 (PDT)
Return-Path: <AN7Q6H-BYEAH-Q3PHR-ISR86-M9HESC-H-M2-20100820-0880a9a4f23ff4aaca@dellcanada.bounce.ed10.net>
Received: from dellcanada.outbound.ed10.com (dellcanada.outbound.ed10.com [64.28.91.220])
        by mx.google.com with ESMTP id p7si1376922vch.147.2010.08.20.07.18.20;
        Fri, 20 Aug 2010 07:18:21 -0700 (PDT)
Received-SPF: pass (google.com: domain of AN7Q6H-BYEAH-Q3PHR-ISR86-M9HESC-H-M2-20100820-0880a9a4f23ff4aaca@dellcanada.bounce.ed10.net designates 64.28.91.220 as permitted sender) client-ip=64.28.91.220;
DomainKey-Status: good
Authentication-Results: mx.google.com; spf=pass (google.com: domain of AN7Q6H-BYEAH-Q3PHR-ISR86-M9HESC-H-M2-20100820-0880a9a4f23ff4aaca@dellcanada.bounce.ed10.net designates 64.28.91.220 as permitted sender) smtp.mail=AN7Q6H-BYEAH-Q3PHR-ISR86-M9HESC-H-M2-20100820-0880a9a4f23ff4aaca@dellcanada.bounce.ed10.net; domainkeys=pass [email protected]
Return-Path: <AN7Q6H-BYEAH-Q3PHR-ISR86-M9HESC-H-M2-20100820-0880a9a4f23ff4aaca@dellcanada.bounce.ed10.net>
DomainKey-Signature: q=dns; a=rsa-sha1; c=nofws;
	s=ED2006-12; d=canada.dell.com;
	h=Received:Date:Content-Type:Content-Transfer-Encoding:MIME-Version:From:Reply-To:To:Subject:Message-Id:X-Mail-From:X-Match:X-RCPT-To:X-Mailer:X-Probability-Threshold;
	b=hdG8BzxXmO6eJwWCswst0KWrpLhojFmy1i+8ZCZXtz5JFAo9gnHHJt1uFPFb9Ykf
	VS2o4BSTmi+hPc3IbgwJBpTEFLyrYtHYhQuIlz+3HdrU6QNW0cZSDZv4rgOryKr0
Received: from [127.0.0.1] ([127.0.0.1:34695])
	by bm1-15.bo3.e-dialog.com (envelope-from <AN7Q6H-BYEAH-Q3PHR-ISR86-M9HESC-H-M2-20100820-0880a9a4f23ff4aaca@dellcanada.bounce.ed10.net>)
	(ecelerity 2.2.2.41 r(31179/31189)) with ECSTREAM
	id 98/A4-10680-6AE8E6C4; Fri, 20 Aug 2010 10:18:14 -0400
Date: Fri, 20 Aug 2010 10:18:14 -0400
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
From: "Dell | Home" <[email protected]>
Reply-To: "Dell | Home" <[email protected]>
To: [i]redacted[/i]
Subject: Dell coupon offers! Save up
 to $500 on select systems
Message-Id: <26492-2538-AN7Q6H-BYEAH-Q3PHR-ISR86-M9HESC-H-M2-20100820-0880a9a4f23ff4aaca@e-dialog.com>
X-Mail-From: AN7Q6H-BYEAH-Q3PHR-ISR86-M9HESC-H-M2-20100820-0880a9a4f23ff4aaca@dellcanada.bounce.ed10.net
X-Match: dellcanada.bounce.ed10.net
X-RCPT-To: [i]redacted[/i]
X-Mailer: EDMAIL R6.00.02
X-Probability-Threshold: 55

Conversely, here's a real spam - a scammer trying one of the "411" scams ("I got lotsa money to smuggle out of Nigeria, I need your help").
Note that the From line (bolded) doesn't match the Received lines; From claims the sender is using a gmail account, but the Received line
says it came from Yahoo. So the sender is faked.
Code:
Delivered-To: [i]redacted[/i]
Received: by 10.204.84.104 with SMTP id i40cs75087bkl;
        Fri, 20 Aug 2010 08:04:02 -0700 (PDT)
Received: by 10.142.147.7 with SMTP id u7mr1087471wfd.216.1282316641298;
        Fri, 20 Aug 2010 08:04:01 -0700 (PDT)
Return-Path: <[email protected]>
[b]Received: from n10.bullet.mail.ac4.yahoo.com (n10.bullet.mail.ac4.yahoo.com [76.13.13.238])
        by mx.google.com with SMTP id d7si2081705vcm.150.2010.08.20.08.03.59;
        Fri, 20 Aug 2010 08:04:00 -0700 (PDT)[/b]
Received-SPF: neutral (google.com: 76.13.13.238 is neither permitted nor denied by domain of [email protected]) client-ip=76.13.13.238;
Authentication-Results: mx.google.com; spf=neutral (google.com: 76.13.13.238 is neither permitted nor denied by domain of [email protected]) [email protected]; dkim=pass (test mode) [email protected]
Received: from [76.13.12.94] by n10.bullet.mail.ac4.yahoo.com with NNFMP; 20 Aug 2010 15:03:59 -0000
Received: from [98.137.27.132] by t2.bullet.mail.ac4.yahoo.com with NNFMP; 20 Aug 2010 15:03:59 -0000
Received: from [98.137.27.130] by t4.bullet.mail.gq1.yahoo.com with NNFMP; 20 Aug 2010 15:03:59 -0000
Received: from [127.0.0.1] by omp204.mail.gq1.yahoo.com with NNFMP; 20 Aug 2010 15:03:59 -0000
X-Yahoo-Newman-Property: ymail-3
X-Yahoo-Newman-Id: [email protected]
Received: (qmail 69085 invoked by uid 60001); 20 Aug 2010 15:03:58 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s1024; t=1282316638; bh=BS/I+0yujhz8X3ENOK1FuSoa6OZK10oCbzFT3J3MtCw=; h=Message-ID:X-YMail-OSG:Received:X-RocketYMMF:X-Mailer:Date:From:Reply-To:Subject:To:MIME-Version:Content-Type:Content-Transfer-Encoding; b=mqcODRKv9b/L+gsHRPWD5g5LovSU8B7NfF4wu42z0m0nPQ9N4kE7aCJDOXchDnDx518DzqBu61ba5P3Tk4yhghwVh85AQICYeZPKAZshDBT4TybB3gjoAK3epF81c5+sTf12pIgZgTCXaB25nvks4Trmu+yjkQV6d4a8G1eKuH8=
Message-ID: <[email protected]>
X-YMail-OSG: nxPJy_YVM1kA0k2DaV59wVqJ7bJP8PWZqyBTzloArboi1N6
 ud2jNH3kp3.Ntg3f5JdQh8FoyDXyLJoXFqFKFK4jriUsysOXbgPD11U2OGwy
 Fwbguv6Nd_A1In7DM53cqnkOGHudryihN..KApFhO_aj_JuVK3J8_99PUHX7
 V15hDhel4tnYM36p8Iwd92rbRYE8iKvzbQpF7waaT8LHRXLYM2vrvlhbVg7e
 iU3Oj1Knd.mLcrsYTWvIk8.yCiVl3R6vOPBnQCzMUccIZu_.2yZwnPKaF6LE
 gjFIlJFKV_LyIV5MG2G0y2mmc9N2OrvrDrmIVW_T27bEHMvSzAdZgtbX8kE.
 xgLyfT5oRBwv4q8n2XC2yJRat4w2iWIZLrrIRmpuLRQN_2Plrm4gcCz1RyIv
 Uo_rZhZFVFzdFTQoIx6rL6L7UipJLykuO5kpwByAaBjrLKQa8cOL0xpv1Nhm
 4ij8MvG7yonuBrCMWFDOO3ViBcFzafvYPGAj4KGiRniVL1B_PCItEBsQ7Pqb
 JlLBsHx_j.7tOcIIuPx3mqluQaw1A0qD58Mkan_1zF6zlhAxo0RBlnnS6N5p
 hhcH4RurHl9Nxxb6z7.7kpwnlCvHzOtI5L2Lgwd6onZ0HVzD8m8hhuCd1cvH
 zexSn7bA.E_.rMiSUO2EF27cPZ1.2fEpiL9AzTNspGYzCGpElGxm_zomqDjl
 l8dJDQaZGvOqagMRfCcDi
Received: from [41.203.224.199] by web120103.mail.ne1.yahoo.com via HTTP; Fri, 20 Aug 2010 08:03:58 PDT
X-RocketYMMF: john_lee4448
X-Mailer: YahooMailClassic/11.3.2 YahooMailWebService/0.8.105.279950
Date: Fri, 20 Aug 2010 08:03:58 -0700 (PDT)
[b]From: amirah ahmed <[email protected]>[/b]
Reply-To: [email protected]
Subject: Hello,
To: undisclosed recipients: ;
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable
 
Arghh. I just tried to see how one would view the message source in Outlook, since that's what most people use. Apparently it isn't possible by default; Microsoft apparently thinks you need to be protected from the raw messages.

:boggled:

Wait. You can view what's important without opening the message. Right click on the message and select Options... At the bottom of the dialog that opens, you should see Internet Headers. This contains the stuff I posted above.

There's still no View Source, though.

Apparently older versions of Outlook may need a registry setting changed to enable this, though.
 
Last edited:
I don't understand how an email address can be faked. I looked at my MSN and Yahoo accounts, and I don't see how you could do that without knowing the other person's password. But then I'm not a spammer. I've had the same thing happen to me quite a bit lately with my Yahoo account. I've checked with others in my contacts list and so far no one else has gotten any spam from my address-------only from me to me.
 
As I mentioned, it's easy. In an e-mail - which is sent as text - the hidden line From: indicates the sender. Nobody validates it; I can easily send an e-mail with the From line reading From: [email protected].

Most e-mail applications or web mail (such as Yahoo) don't let you change what goes in this line directly. Some, such as G-mail, let you send "from another address", although they have some checks built-in so you can't use an arbitrary address. This works by a) validating that you own the "other address" and b) changing the From: line.

Spammers use their own programs and (of course) skip step a) above.
 

ISF - Join now!

Every member here is approved by hand. No bots, no spam, just people who care about evidence and honest debate.

Membership is free!

Create your free account

Back
Top Bottom