Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.

View this topic in a long page with up to 500 replies per page Watch this topic Create new topic
Prev1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13Next
4269 posts

Uber Geek


  Reply # 759602 11-Feb-2013 16:10 Send private message quote this post

cyril7: Hi Mike, you will not see anything in the sent items folder even on the web interface, your contacts list was harvested by this rouge who then sent the emails outside of the Yahoo system.

Cyril


Although it still goes though the outgoing yahoo servers, as can be seem in the email headers. They probably are just bypassing the webmail interface with their own scripts.



900 posts

Ultimate Geek


  Reply # 759603 11-Feb-2013 16:12 Send private message quote this post

cyril7: Hi Mike, you will not see anything in the sent items folder even on the web interface, your contacts list was harvested by this rouge who then sent the emails outside of the Yahoo system.


All the headers I've seen indicate that the Yahoo SMTP servers were the ones delivering from victim to recipient.  

Yahoo is/were the ones delivering the spam from their network.  Which indicates that either
 1. they were open relay - unlikely
 2. the attack used the webmail system to send
 3. the attack was able to harvest (or change) username/password and authenticate to the SMTP server
 4. the attack used their own yahoo account to send a joe-job

I'd say 2 or 3 were most likely.





---
James Sleeman

My hobby - listing small amounts of interesting/useful hobby electronic components hardware and stuff on Trademe for cheap, all good geek stuff for the "maker" revolution ;-)

Tip for Trademe addicts: install an addon for your browser to get thumbs for all listings.  

5678 posts

Uber Geek

Trusted
Subscriber

  Reply # 759607 11-Feb-2013 16:14 Send private message quote this post

ok ok, but essentially it was not processed as usual, so does not appear in your sent folder.

Cyril

209 posts

Master Geek

Trusted

  Reply # 759608 11-Feb-2013 16:15 Send private message quote this post

sleemanj:
cyril7: Hi Mike, you will not see anything in the sent items folder even on the web interface, your contacts list was harvested by this rouge who then sent the emails outside of the Yahoo system.


All the headers I've seen indicate that the Yahoo SMTP servers were the ones delivering from victim to recipient.  

Yahoo is/were the ones delivering the spam from their network.  Which indicates that either
 1. they were open relay - unlikely
 2. the attack used the webmail system to send
 3. the attack was able to harvest (or change) username/password and authenticate to the SMTP server
 4. the attack used their own yahoo account to send a joe-job

I'd say 2 or 3 were most likely.



Cyril, Andy, Matt, James, thank you for the explanantions.




Michael Skyrme - Instrumentation & Controls

4757 posts

Uber Geek

Trusted
Subscriber

  Reply # 759615 11-Feb-2013 16:30 Send private message quote this post

We just got a flood of new xtra.co.nz ones and customers have started calling again!

173 posts

Master Geek


  Reply # 759629 11-Feb-2013 16:58 Send private message quote this post

Well done - you're on slashdot... tech.slashdot.org/story/13/02/11/0029201/widespread-compromise-of-yahoo-backed-email-in-new-zealand

177 posts

Master Geek

Subscriber

  Reply # 759646 11-Feb-2013 17:20 Send private message quote this post

The problem is NOT fixed, spam messages from Xtra/Yahoo are still arriving as of 4.30 pm today.  Same type of message.

Just A Geek
1582 posts

Uber Geek

Trusted
Subscriber

  Reply # 759671 11-Feb-2013 17:59 Send private message quote this post

The "incident" has hit slashdot now (The top story) and this thread is linked off it :-) Look out geekzone.

I got /.ed once .. Wasn't very nice :-)




BDFL
43785 posts

Uber Geek

Administrator
Trusted
Geekzone
Subscriber

  Reply # 759673 11-Feb-2013 18:01 Send private message quote this post

Thanks again to whoever posted the link. And don't worry, /. is not what it used to be...





4269 posts

Uber Geek


  Reply # 759680 11-Feb-2013 18:12 Send private message quote this post

TVNZ has it as one of their top stories, and they said it was now fixed.

5 posts

Wannabe Geek


  Reply # 759858 12-Feb-2013 05:59 Send private message quote this post

They defiantly still have issues, maybe the exploit has been resolved, but plenty of email accounts are still compromised.
MTA's I monitor have been receiving 200+ spam emails an hour all night from Xtra & Yahoo addresses.

67 posts

Master Geek


  Reply # 759882 12-Feb-2013 08:52 Send private message quote this post

I have changed my username password on Yahoo, do I also need to change my username.xadsl password as well.

86 posts

Master Geek


  Reply # 759886 12-Feb-2013 09:00 Send private message quote this post

Looks like round two of the phishing attacks have started.

My parent's business received a call from "Telecom" telling them that they needed to change their broadband and email passwords. Funny thing is that while they're with Telecom their email is on the business platform which I believe is unrelated to Yahoo.

I got a panicked call about it so told them it was likely fake and to ring back Xtra to get confirmation.

If it does turn out true though it will change the hack substantially.

166 posts

Master Geek


  Reply # 759891 12-Feb-2013 09:07 Send private message quote this post

Klathman: Looks like round two of the phishing attacks have started.

My parent's business received a call from "Telecom" telling them that they needed to change their broadband and email passwords. Funny thing is that while they're with Telecom their email is on the business platform which I believe is unrelated to Yahoo.

I got a panicked call about it so told them it was likely fake and to ring back Xtra to get confirmation.

If it does turn out true though it will change the hack substantially.


Thanks for letting us know.  Sounds like people in NZ are getting on the bandwagon maybe?  Guess it reminds everyone not to respond to unsolicited communication.

Hopefully Xtra will be a bit more proactive today in informing all Xtra/ADSL users via the press, emails etc.

904 posts

Ultimate Geek

Trusted
Telecom NZ

  Reply # 759920 12-Feb-2013 10:03 Send private message quote this post

Hey everyone, sorry I have been MIA yesterday.  Was a tad of a crazy day.

I'll be online a bit more today.

If anyone has any recent spam they got today or late last night ideally could you forward the full email including the headers to our team mailbox ort@telecom.co.nz and I will forward them on.

If you're using a web-mail client you can find some instructions here:

http://telecom.custhelp.com/app/answers/detail/a_id/4019

If you're using a full client such as Outlook or Thunderbird on your computer

http://telecom.custhelp.com/app/answers/detail/a_id/14504

It's still being actively investigated and some recent spam emails including full headers would be extremely useful.





I work for Telecom, but as always my views are my own.

Prev1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13Next
View this topic in a long page with up to 500 replies per page Watch this topic Create new topic



Twitter »
Follow us to receive Twitter updates when new discussions are posted in our forums:



Follow us to receive Twitter updates when news items and blogs are posted in our frontpage:



Follow us to receive Twitter updates when new jobs are posted to our jobs board:



Follow us to receive Twitter updates when tech item prices are listed in our price comparison site:




News »

Trending now »
Hot discussions in our forums right now:

Fecked up religious people strike again :-(
Created by Mark, last reply by BurningBeard on 25-May-2013 00:03 (84 replies)
Pages... 4 5 6


Cannabis is illegal yet we have really strong 'legal highs' ?
Created by qwerty7, last reply by freitasm on 23-May-2013 23:20 (74 replies)
Pages... 3 4 5


Xbox One
Created by DjShadow, last reply by Kingy on 24-May-2013 13:48 (68 replies)
Pages... 3 4 5


A new project coming to Geekzone
Created by freitasm, last reply by l43a2 on 24-May-2013 23:02 (342 replies)
Pages... 21 22 23


Troublesome transition to VDSL
Created by oseiler, last reply by michaelmurfy on 24-May-2013 13:57 (18 replies)
Pages... 2


HTC One (2013) owners' discussion
Created by Dingbatt, last reply by wlfkfgkwlaktka on 24-May-2013 15:49 (1564 replies)
Pages... 103 104 105


Monolithic Cement Sheet cladding mid 80s house - "leaky home" or not?
Created by joker97, last reply by mattwnz on 24-May-2013 23:46 (15 replies)

Warning - Users with Tenda ADSL modem
Created by Psi, last reply by Psi on 24-May-2013 22:01 (44 replies)
Pages... 2 3



Geekzone Jobs »
Most recent NZ jobs in technology:

Organisational Change Analyst
Posted 24-May-2013 19:28

Dedicated Java Developer/ Technical lead
Posted 24-May-2013 18:28

Account Manager - IT/Telco
Posted 24-May-2013 18:28

Commercial Java Developer
Posted 24-May-2013 18:28

Senior DB2 Database Administrator
Posted 24-May-2013 18:28

Technical BA
Posted 24-May-2013 18:28

OSS Systems Engineer
Posted 24-May-2013 18:28


Geekzone Live »
Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.

Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.

Alternatively, you can receive a daily email with Geekzone updates.