Forum: Geek Forum
Topic: Really f'ing wierd.
started by: miNus

Posted by miNus on Nov. 03 2001,01:31
Ok, so I get this email from this guy today. It was no one I know, and the message was intended for someone else. So I figure he typed the to: field in wrong.

I look and it says to: christopherrogers@cspgroup.com

*scratches head*

What the fuck? My email is christopherrico@home.com so there is a similarity... but still... what the fuck?

So I reply to the guy who emailed me, telling him that it somehow got sent to me by mistake, and that he should try to send the message again.

I check my email a bit later and I get this:

quote:

This Message was undeliverable due to the following reason:

Each of the following recipients was rejected by a remote mail server.
The reasons given by the server are included to help you determine why
each recipient was rejected.

Recipient: <jan691@swan.ac.uk>
Reason: Unknown local part jan691 in <jan691@swan.ac.uk>


Please reply to Postmaster@home.com
if you feel this message to be in error.


I'm very confused here... any of you network geeks care to shed some light on this?

Maybe my ISP's email server has dyslexia or something? Once again: what the fuck?


Posted by [liquid] meta on Nov. 03 2001,01:44
did it seem like an important email? or just some random crap?

if it's the latter it was most likely sent through a mass mailer with you and maybe 100 others in the BCC. i get those a lot.

if it's the former then possibly his mail server went down when you went to send him the email.

oh wait, i forget that i'm completely and utterly wrong in everything and in every way.


Posted by miNus on Nov. 03 2001,01:47
Here's his original message:
quote:
Hey Mike I just got in I will give you a buzz in an hour or so

I don't think he would bother to mass email that. And it wasn't a CC: it was TO: christopherrogers@cspgroup.com

christopherrico@home.com is nowhere in the header at all.

Here's the header:

quote:

Return-Path: <jan691@swan.ac.uk>
Received: from mh12-tx.mail.home.com ([65.10.73.160])
by femail35.sdc1.sfba.home.com
(InterMail vM.4.01.03.20 201-229-121-120-20010223) with ESMTP
id <20011103170040.DLOG14847.femail35.sdc1.sfba.home.com@mh12-tx.mail.home.com>;
Sat, 3 Nov 2001 09:00:40 -0800
Received: from mx12-tx.mail.home.com (mx12-tx.mail.home.com [65.10.73.156])
by mh12-tx.mail.home.com (8.9.3/8.9.0) with ESMTP id JAA28655;
Sat, 3 Nov 2001 09:00:39 -0800 (PST)
From: jan691@swan.ac.uk
Received: from ns2.storeyourwebpages.com ([4.21.122.6])
by mx12-tx.mail.home.com (8.11.1/8.11.1) with ESMTP id fA3H0cO29136;
Sat, 3 Nov 2001 09:00:38 -0800 (PST)
Date: Sat, 3 Nov 2001 11:59:40 -0500
Message-Id: <200111031659.fA3Gxed03568@ns2.storeyourwebpages.com>
Reply-To: <jan691@swan.ac.uk>
To: <christopherrogers@cspgroup.com>
Subject: Hey Mike igdfie
X-Mailer: Microsoft Outlook 8.5, Build 4.71.2173.0

This message has been edited by miNus on November 03, 2001 at 08:48 PM


Posted by Dysorderia on Nov. 03 2001,02:22
happened to me before
i have got mails that were addressed to beng65@yahoo.com when my mail addy is beng64@yahoo.com....
ive got other mails that weren't addressed to me, but i can't remember any more examples of the top of my head..........

oh yeah, don't bother trying to annoy me since i delete any mail where i don't recognise the sender.

*edit* Minus, it's spoofed.
Received: from ns2.storeyourwebpages.com ([4.21.122.6])

this is the last From: header.
There is no address for the mail server of swan.ac.uk.

if the mail wasn't spoofed, the last From: header would read like this:
Received: from smtp.swan.ac.uk

------------------
Bill Gates's Honeymoon

After Bill Gates's wedding night, his wife finally knew why he called his company Microsoft.

This message has been edited by Dysorderia on November 03, 2001 at 09:33 PM


Posted by incubus on Nov. 03 2001,04:35
quote:
Originally posted by Dysorderia:
*edit* Minus, it's spoofed.
[b]Received: from ns2.storeyourwebpages.com ([4.21.122.6])

this is the last From: header.
There is no address for the mail server of swan.ac.uk.

if the mail wasn't spoofed, the last From: header would read like this:
Received: from smtp.swan.ac.uk

[/B]


I'm always suspicious receiving mail from a nameserver So I telnetted there on port 25 to see if it's an open relay:

code:

220 ns2.storeyourwebpages.com ESMTP Sendmail 8.11.2/8.11.0; Sun, 4 Nov 2001 02:30:08 -0500
250 ns2.storeyourwebpages.com Hello pc-62-31-16-85-sh.blueyonder.co.uk [62.31.16.85], pleased to meet you
250 2.1.0 billg@microsoft.com... Sender ok
550 5.7.1 incubus@ice-breaker.net... Relaying denied
550 5.7.1 christopherrico@home.com... Relaying denied

...so it's not an open relay. Hmmm ... interesting.

------------------
"just pressin y0 butt0ns f00" -- miNus


Powered by Ikonboard 3.1.4 © 2006 Ikonboard