View Single Post
Old 02-26-2013, 04:04 PM   #11
BloodFetish
First Line Centre
 
Join Date: Aug 2009
Location: Coquitlam, BC
Exp:
Default

The name that appears in the subject line may not necessary be hacked, rather the spammers are spoofing the 'real name'. The important bit is the actual sending email address, which you can find in the message source.

The name that appears in the From field or subject line - I have no idea if this comes from a contact list, or a web scrape, or god knows where else.

So far we're seeing these coming from Yahoo.ca, Yahoo.com, and Rogers.com (who also use Yahoo's servers)

The sending email accounts are real (ie: not spoofed) so backscatter doesn't help us. We've resorted to adding content filtering rules to weed these out. We use Alt-N's MDaemon for mail. If anyone else uses the same software I'd be happy to help.
BloodFetish is offline   Reply With Quote