origin of malicious email
Author
Discussion

bindit

Original Poster:

2,364 posts

291 months

Wednesday 14th April 2004
quotequote all
My girlfreind has recieved a nasty email (only one email at this point), with the kind of detail in it that only a handful of people would know.

It was sent from a Hotmail account, is it possible to get the IP address somehow?

We think we know who it is and as she's had email correspondence with this person on a normal footing, i thought maybe we could do a comparison?

Any help would be greatly appreciated as this person has caused an awful lot of upset.

apeebles

267 posts

310 months

Wednesday 14th April 2004
quotequote all
Very difficult to trace I.e. Setup an account in a cybercafe and send nasty email. I would send a complaint to hotmail who could then close the account and if necessary also with the police.

JamieBeeston

9,294 posts

291 months

Wednesday 14th April 2004
quotequote all
You Could try pasteing the headers here, but likely they will only show the hotmail server itself,

your only real recourse would be to contact the police, who in turn could contact Hotmail and ask them for the IP of the user at the time (you could try asking them yourself, but I am sure the DPA would stop them)

Hope you catch them.

GL.

TheHobbit

1,189 posts

277 months

Wednesday 14th April 2004
quotequote all
the originating clients IP address is included in the headers of the mail if it was actually sent from Hotmail, rather than just spoofed.

Bonce

4,339 posts

305 months

Wednesday 14th April 2004
quotequote all
Tell her not to respond to it or acknowledge it in any way whatsoever, and if she found the content of that one upsetting, tell her not to open any more emails from that address.

Best way to beat that kind of thing is to completely ignore it. If you let them get to you, they've won.

rpguk

4,513 posts

310 months

Thursday 15th April 2004
quotequote all
Not sure how she's picking up the email, but if its in Outlook then right click on the mail from the inbox and select options (other mail clients and web mail should let you see the full headers as well, check the help manual). You can then see the headers, now assuming its a proper hotmail account rather then spoofed there should be a line that says

"X-Originating-IP: [???.??.??.??]" (where the question marks will be numbers)

Now if you go to www.ripe.net/db/whois/whois.html and search the IP you should get the owner of the IP (usually the ISP they are using)

This might help you narrow things down.

Of course if they used an internet cafe or another computer then the above isn't of much use, but most people think that by using a hotmail account they are pretty much anonomyous and don't bother disguising themselves anymore.

>> Edited by rpguk on Thursday 15th April 15:59