Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.




55 posts

Master Geek
+1 received by user: 1


Topic # 188970 11-Dec-2015 22:10
Send private message

Hi all, apologies if this is the wrong forum. Just checking my gmail account I have an email from Have I been pwned asking me to confirm my registration stating that I, or someone else, has subscribed my email address to their service and asking me to verify my email address. I certainly haven't and subscribed and suspected a phish, a quick google doesn't bring up anything obvious eg it's a known phish. At the bottom of the email it states what the email was sent from someone at a certain IP address, a quick check shows that it is my IP address. I'm checking from my mobile device over Spark using the wap.telecom.co.nz APN.

Any ideas??

Many thanks

Paul 

Create new topic


55 posts

Master Geek
+1 received by user: 1


  Reply # 1448934 11-Dec-2015 22:12
Send private message

Sorry the email says that it was initiated from someone at my IP address.....

3081 posts

Uber Geek
+1 received by user: 846

Trusted

  Reply # 1448937 11-Dec-2015 22:23
Send private message

So you received an email from this site?

https://haveibeenpwned.com 

If so it's probably not phishing or a hack - it's a fairly well known and IMO useful service\site.  I've signed up for it.  Perhaps you left your device\PC unattended and unlocked and someone signed you up to it to make a point or as a joke?

 
 
 
 




55 posts

Master Geek
+1 received by user: 1


  Reply # 1448943 11-Dec-2015 22:45
Send private message

Hi sidefx

email came from noreply@haveibeenpwned.com

I checked my history and it doesn't appear as though someone has been having fun but I guess it's a possibility....

Cheers

Paul

3081 posts

Uber Geek
+1 received by user: 846

Trusted

  Reply # 1448946 11-Dec-2015 23:05
Send private message

Yup, that's where the legit signup email I got after I signed up came from. If you didn't sign up to it just ignore it. 

BDFL - Memuneh
59392 posts

Uber Geek
+1 received by user: 10604

Administrator
Trusted
Geekzone
Lifetime subscriber

  Reply # 1448976 11-Dec-2015 23:35
Send private message

Where an email comes from means nothing - this is easily spoofed. The most important thing is really to check where the link for confirmation takes you - is it the actual site or some other domain?

And yes, it's a double opt-in: you enter your email address and instead of accepting it as a registration it sends out a confirmation with a link to verify the address to subscribe. 

The beauty of this is that other people can't sign you up for unwanted mailing lists.

If you didn't do it, ignore. Move along.





gzt

9259 posts

Uber Geek
+1 received by user: 1318


  Reply # 1448978 11-Dec-2015 23:52
Send private message

[Edit: assuming it is genuine as per M's comments:]

That's kind of interesting. How many devices use that ip address? I assume it is dynamic?

3081 posts

Uber Geek
+1 received by user: 846

Trusted

  Reply # 1449134 12-Dec-2015 11:46
Send private message

@gzt The fact the signup request came from the OPs IP address is a bit odd, hence why I asked if someone may have got access to one of his devices and been playing silly buggers. I don't think anything in @freitasm's post was attempting to explain how it may have come from the OPs IP, just that the whole activation through email confirmation is good and that the sender of the reply (noreply@haveibeenpwned.com) can very very very easily be spoofed - though generally decent spam filters are good at picking this up - hence why it's important to verify that any links in the email actually go to the proper\expected site. 

Of course if one is using a wifi network at home\work someone every device inside the network may (and probably will) share the one external public IP address, though OP says they were doing it from mobile device so that may be a bit different... though I *think* mobile phones are NAT'd in a similar way?

gzt

9259 posts

Uber Geek
+1 received by user: 1318


  Reply # 1449196 12-Dec-2015 14:43
Send private message

Reboot the mobile device and try again. The mobile device may likely get a new ip address. That will be interesting.



55 posts

Master Geek
+1 received by user: 1


  Reply # 1449280 12-Dec-2015 18:04
Send private message

Hi all

Rebooted my phone and still have the same IP, I'm pretty sure the wap APN NATs. Just a bit more info, I got the email at 8.15 last night, from around 6.50 till just after 8pm I was in a graduation and no one had access to my phone barring me

Cheers

Paul

Create new topic



Twitter »

Follow us to receive Twitter updates when new discussions are posted in our forums:



Follow us to receive Twitter updates when news items and blogs are posted in our frontpage:



Follow us to receive Twitter updates when tech item prices are listed in our price comparison site:





News »

$3.74 million for new electric vehicles in New Zealand
Posted 17-Jan-2018 11:27


Nova 2i: Value, not excitement from Huawei
Posted 17-Jan-2018 09:02


Less news in Facebook News Feed revamp
Posted 15-Jan-2018 13:15


Australian Government contract awarded to Datacom Connect
Posted 11-Jan-2018 08:37


Why New Zealand needs a chief technology officer
Posted 6-Jan-2018 13:59


Amazon release Silk Browser and Firefox for Fire TV
Posted 21-Dec-2017 13:42


New Chief Technology Officer role created
Posted 19-Dec-2017 22:18


All I want for Christmas is a new EV
Posted 19-Dec-2017 19:54


How clever is this: AI will create 2.3 million jobs by 2020
Posted 19-Dec-2017 19:52


NOW to deploy SD-WAN to regional councils
Posted 19-Dec-2017 19:46


Mobile market competition issues ComCom should watch
Posted 18-Dec-2017 10:52


New Zealand government to create digital advisory group
Posted 16-Dec-2017 08:47


Australia datum changes means whole country moving 1.8 metres north-east
Posted 16-Dec-2017 08:39


UAV Traffic Management Trial launching today in New Zealand
Posted 12-Dec-2017 16:06


UFB connections pass 460,000
Posted 11-Dec-2017 11:26



Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.

Alternatively, you can receive a daily email with Geekzone updates.