fraud emails coming from joomla

If you have any 'mechanical' forum or Joomla! sites related issues/suggestions, please contact the Sites & Infrastructure Workgroup here.

Moderators: brad, Tonie

Forum rules
Forum Rules
READ ME <-- please read before posting, this means YOU.
Post Reply
daczo
Joomla! Fledgling
Joomla! Fledgling
Posts: 2
Joined: Mon Jan 28, 2008 10:07 pm

fraud emails coming from joomla

Post by daczo » Mon Jan 28, 2008 10:13 pm

Hello
I just got a fraud email (pretending to be from bank) coming from your IP, this is the email header:

Code: Select all

Return-Path: <[email protected]>
Received: from xxx.com.au ([xxx.xxx.xxx.xxx] verified)
  by xxx.com.au (CommuniGate Pro SMTP 5.2c4)
  with ESMTPS id 3225994 for [email protected]; Tue, 29 Jan 2008 08:54:17 +1100
Received-SPF: none (xxx.com.au: 69.72.133.226 is neither permitted nor denied by domain of localhost.joomlanet.com) client-ip=69.72.133.226; [email protected]; helo=localhost.joomlanet.com;
Received: from joomlanet.com ([69.72.133.226] helo=localhost.joomlanet.com)
   by fish.ish.com.au with esmtps (TLSv1:AES256-SHA:256)
   (Exim 4.43)
   id 1JJbxh-0003cw-Ep
   for [email protected]; Tue, 29 Jan 2008 08:56:26 +1100
Received: from nobody by localhost.joomlanet.com with local (Exim 4.63)
   (envelope-from <[email protected]>)
   id 1JJbuy-0006fc-Be
   for [email protected]; Mon, 28 Jan 2008 16:53:28 -0500
To: [email protected]
Subject: account suspension
From: St. George Bank <[email protected]>
Reply-To: [email protected]
MIME-Version: 1.0
Content-Type: text/html
Content-Transfer-Encoding: 8bit
Message-Id: <[email protected]>
Date: Mon, 28 Jan 2008 16:53:28 -0500
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - localhost.joomlanet.com
X-AntiAbuse: Original Domain - xxx.com.au
X-AntiAbuse: Originator/Caller UID/GID - [99 500] / [47 12]
X-AntiAbuse: Sender Address Domain - localhost.joomlanet.com
X-Source:
X-Source-Args: /usr/local/apache/bin/httpd -DSSL
X-Source-Dir: joomlahacks.com:/public_html/chat
X-Spam-Score: 1.8 (+)
X-Spam-Report:    0.8 HTML_IMAGE_ONLY_32     BODY: HTML: images with 2800-3200 bytes of words
    0.0 MIME_HTML_ONLY         BODY: Message only has text/html MIME parts
    1.0 HTML_MIME_NO_HTML_TAG  HTML-only message, but there is no HTML tag


Please ensure security of your server.

Cheers
Marcin

User avatar
brad
Joomla! Hero
Joomla! Hero
Posts: 2212
Joined: Fri Aug 12, 2005 12:38 am
Skype: tested
Location: Sydney - Australia
Contact:

Re: fraud emails coming from joomla

Post by brad » Mon Jan 28, 2008 10:21 pm

Thanks for dropping in to report this.. however, none of this originates from any of our servers. That is not our IP address either. You may wish to contact the IP owner/operator.
Brad Baker - Joomla! Core Team, Sites & Infrastructure.
http://www.rochen.com - Managed Dedicated, Reseller & Multiple Domain Hosting.
http://www.joomlatutorials.com <-- Joomla! 1.5 & 1.0.x
^New Joomla 1.5 Tutorials are out!

daczo
Joomla! Fledgling
Joomla! Fledgling
Posts: 2
Joined: Mon Jan 28, 2008 10:07 pm

Re: fraud emails coming from joomla

Post by daczo » Mon Jan 28, 2008 10:25 pm

Host command points the dns to your place :

Code: Select all

$ host 69.72.133.226
226.133.72.69.in-addr.arpa domain name pointer joomlanet.com.
$


Marcin

User avatar
brad
Joomla! Hero
Joomla! Hero
Posts: 2212
Joined: Fri Aug 12, 2005 12:38 am
Skype: tested
Location: Sydney - Australia
Contact:

Re: fraud emails coming from joomla

Post by brad » Mon Jan 28, 2008 11:00 pm

Brad Baker - Joomla! Core Team, Sites & Infrastructure.
http://www.rochen.com - Managed Dedicated, Reseller & Multiple Domain Hosting.
http://www.joomlatutorials.com <-- Joomla! 1.5 & 1.0.x
^New Joomla 1.5 Tutorials are out!

easywebhost
Joomla! Apprentice
Joomla! Apprentice
Posts: 5
Joined: Wed Jan 30, 2008 12:36 pm

Re: fraud emails coming from joomla

Post by easywebhost » Wed Jan 30, 2008 12:51 pm

Damn i hate this spam... will it ever stop ?

User avatar
brad
Joomla! Hero
Joomla! Hero
Posts: 2212
Joined: Fri Aug 12, 2005 12:38 am
Skype: tested
Location: Sydney - Australia
Contact:

Re: fraud emails coming from joomla

Post by brad » Wed Jan 30, 2008 8:03 pm

easywebhost wrote:Damn i hate this spam... will it ever stop ?


When the host in question takes actions and cleans up the account, yes. Sadly, even if I wanted to, in this case there is nothing we can do, as we have no association with this domain name/user.
Brad Baker - Joomla! Core Team, Sites & Infrastructure.
http://www.rochen.com - Managed Dedicated, Reseller & Multiple Domain Hosting.
http://www.joomlatutorials.com <-- Joomla! 1.5 & 1.0.x
^New Joomla 1.5 Tutorials are out!

easywebhost
Joomla! Apprentice
Joomla! Apprentice
Posts: 5
Joined: Wed Jan 30, 2008 12:36 pm

Re: fraud emails coming from joomla

Post by easywebhost » Thu Jan 31, 2008 11:27 am

yes you are totally correct. I can see your point.  :D

User avatar
Rochen
Joomla! Intern
Joomla! Intern
Posts: 79
Joined: Wed Aug 17, 2005 3:19 pm
Location: United Kingdom
Contact:

Re: fraud emails coming from joomla

Post by Rochen » Fri Feb 01, 2008 5:09 pm

http://ws.arin.net/whois/?queryinput=69.72.133.226

The organization you need to contact is FortressITX. Simply forward the message with the full message headers to: [email protected]

- Chris
Chris Adams - CEO - Rochen Ltd. - 5 Years Industry Experience!
- Reseller Hosting & Multiple Domain Hosting
- www.rochen.com [b]| forums.rochen.com[/b]


Post Reply