Email Account Attacked

Status
Not open for further replies.
You need to check your sent folder and see if you were actually hacked.

You can send emails from any computer and alter the "from" email address using most email clients. Just because they put your email in the "from" box doesn't mean they hacked into your email. When emails bounce, they automatically go to the "from" address regardless of where the emails originated from.
 
Originally Posted By: 2015_PSD
Originally Posted By: John_Conrad
and make it a difficult password include a capital letter and a symbol of some sort. my only problem with these harder to hack passwords is that I have to write them down until I can remember them, by then it's time to change the password again. so frequency of changing passwords can also help.
Use a known phrase or word that is unique to you in some way (so that you will remember it) and change some of the letters with symbols. For example, Merkava_4 could use this as a password:

M&rk@v@_$

He should not use that now that I have posted it, but you get the idea.


that's a good way!

could one use the same high tech password and then rotate changing only 1 letter or character at a time every time it's time to change password?

say in your example: M&rk@v@_$ when it's time to change, could one go to M&rk@v@_S or is it recommended to come up with an entirely new password?
 
As Alfred_B and Badtlc mention, that actually isn't evidence that your email account was broken into. What those are showing is that someone simply sent out a [censored] of spam and spoofed your address to do so. Basically the spammer sends out their spam with a faked From: address (yours). That's very different from your account actually being broken into, where the attacker can actually look at all your email. Think of someone using the Postal Service to send out a bunch of come-on letters, but using your return address. This makes you get all the non-deliverables, and he doesn't have to deal with it. Same thing is going on here--you're having to deal with all the non-deliverable notifications, and the spammer doesn't.

Spoofing a different sender address is and always has been trivial--it's a design fault of the internet email (SMTP) specs.
 
Originally Posted By: badtlc
You need to check your sent folder and see if you were actually hacked.

You can send emails from any computer and alter the "from" email address using most email clients. Just because they put your email in the "from" box doesn't mean they hacked into your email. When emails bounce, they automatically go to the "from" address regardless of where the emails originated from.

This.
I used to have this happen quite a bit and I decided that since my email started with a "1" it was at the beginning of the email spammer's list of return addresses to use.
Does you email start with a number?
 
Last edited:
Originally Posted By: AlaskaMike


Spoofing a different sender address is and always has been trivial--it's a design fault of the internet email (SMTP) specs.


Yep, back in the day we'd telnet to port 25 on the SMTP server and "speak" the proper protocol to the server, creating mail from "[email protected]" or other such witty e-mail messages.
 
I use Yahoo and was hacked a while back. Apparently they covered their tracks and didn't leave anything in my sent items. Thankfully, they didn't delete anything or lock me out, just spammed everyone in my address book.

You should be able to look in your account log and see the locations where you logged in. If you see something unusual, then yep, probably hacked. Otherwise, it could just be somebody spoofing your e-mail address.

Change your password to be on the safe side anyway.
 
Originally Posted By: John_Conrad
Originally Posted By: 2015_PSD
Originally Posted By: John_Conrad
and make it a difficult password include a capital letter and a symbol of some sort. my only problem with these harder to hack passwords is that I have to write them down until I can remember them, by then it's time to change the password again. so frequency of changing passwords can also help.
Use a known phrase or word that is unique to you in some way (so that you will remember it) and change some of the letters with symbols. For example, Merkava_4 could use this as a password:

M&rk@v@_$

He should not use that now that I have posted it, but you get the idea.
that's a good way! could one use the same high tech password and then rotate changing only 1 letter or character at a time every time it's time to change password? say in your example: M&rk@v@_$ when it's time to change, could one go to M&rk@v@_S or is it recommended to come up with an entirely new password?
The caveat is if you think a keylogger has been installed it does not matter how you increment, but on the odds a keylogger was not installed and as long as the password is not too similar, it would be fine. I use very cryptic passwords on all of my accounts and change them at least once per year.
 
Originally Posted By: javacontour
Originally Posted By: AlaskaMike


Spoofing a different sender address is and always has been trivial--it's a design fault of the internet email (SMTP) specs.


Yep, back in the day we'd telnet to port 25 on the SMTP server and "speak" the proper protocol to the server, creating mail from "[email protected]" or other such witty e-mail messages.


[email protected]

hehehe, the memories......
 
It's not like this is your first day at this Computer-Room. We've been telling members here for years to lose those Ymail and Yahoo email accounts.
Obviously you didn't listen and now you got invaded. Move over to GMail...... much safer.
 
Originally Posted By: dishdude
Does Yahoo offer two step verification?


They do. If your account is signed in from a different unknown computer you need a verification code from Yahoo that is sent to your cell phone number.
 
Originally Posted By: ZeeOSix
Originally Posted By: dishdude
Does Yahoo offer two step verification?


They do. If your account is signed in from a different unknown computer you need a verification code from Yahoo that is sent to your cell phone number.


Well there's no excuse for not having that additional layer of protection activated.
 
Originally Posted By: Triple_Se7en
Move over to GMail...... much safer.


That is a good one. Makes me chuckle every time.
 
I run an antikeylogger on my laptop. Also use a long password. Just a simple phrase that only you would understand.
 
Originally Posted By: Blkstanger
I run an antikeylogger on my laptop.


How does that work and what's it supposed to do? Never heard of an anti-keylogger program.
 
Just me but of all the free email accounts out there,YAHOO is one I wouldnt even touch with a ten-foot pole.


Try Gmail,GMX,etc.
 
I wrote scripts to autogenerate me passwords. I just specify whether I want mine 8, 16, or 32 characters and it spits out the most random alphanumerical and special character sequence you can imagine. Then when the password is registered and the account is working I save it to my passwords list and then I encrypt the list again.
 
Last edited:
Status
Not open for further replies.
Back
Top Bottom