traceing dodgy message

Author
Discussion

billb

Original Poster:

3,198 posts

266 months

Tuesday 8th March 2005
quotequote all
is there anyway of finding out who sent a dodgy message using yahoo web mail?

ta

_Dobbo_

14,393 posts

249 months

Tuesday 8th March 2005
quotequote all
Depends if yahoo has any way of showing the full message headers. If so post them up here (or PM them to me through my profile if you prefer) and I'll tell you where it came from.

billb

Original Poster:

3,198 posts

266 months

Tuesday 8th March 2005
quotequote all
_Dobbo_ said:
Depends if yahoo has any way of showing the full message headers. If so post them up here (or PM them to me through my profile if you prefer) and I'll tell you where it came from.


has come from our network as it has our external ip on it but thats about as much as we can tell

chrisjl

785 posts

283 months

Tuesday 8th March 2005
quotequote all
Reply to it with an HTML message containing an embedded image hosted on a server inside your network, then watch the logs...
Practice first - you might only get one shot, so you'll want to get it right first time.
(Be sure whatever tool you use doesn't embed a copy of the image, or you won't learn anything. I'd use Perl or Tcl or something to generate the message myself)

_Dobbo_

14,393 posts

249 months

Tuesday 8th March 2005
quotequote all
If your network does Network Address translation which I can only assume it does, then unless your NAT device logs traffic then you probably can't do much.

Other than the above proposed (very good) idea of embedding an image on a webserver somewhere on the local LAN, then reply to the email.

When the sender reads the reply, the PC they use will retrieve the image, and the web server log will log which internal IP address accessed the image. Then you have your culprit.

A lot of hassle, so I guess it depends how dodgy is "dodgy"!

chrisjl

785 posts

283 months

Wednesday 9th March 2005
quotequote all
If you want any help with my suggestion, give me a shout (can't do much during the day, but could probably knock something together this evening).

billb

Original Poster:

3,198 posts

266 months

Friday 11th March 2005
quotequote all
chrisjl said:
If you want any help with my suggestion, give me a shout (can't do much during the day, but could probably knock something together this evening).


the seriousness has increased so the trap has been set!! corking idea

_Dobbo_

14,393 posts

249 months

Friday 11th March 2005
quotequote all
Ooooh! Exciting. Let us know if you catch the culprit!

chrisjl

785 posts

283 months

Friday 11th March 2005
quotequote all
_Dobbo_ said:
Ooooh! Exciting.
Indeed.

So, what did you use as the embedded image? The subtle option would be a single pixel transparent GIF, but I think I would have gone for:
Embedded image said:
If you can read this, it's time to start clearing your desk...



Did you send an actual reply, or did you use another address? Can you be sure they'll read it and not just delete it?

Let us know how it goes.

_DeeJay_

4,898 posts

255 months

Friday 11th March 2005
quotequote all
chrisjl said:
If you want any help with my suggestion, give me a shout (can't do much during the day, but could probably knock something together this evening).


That's really quite cunning - I like it!
The more obvious approach would be to check the firewall/proxy log, but this is far more devious

billb

Original Poster:

3,198 posts

266 months

Friday 11th March 2005
quotequote all
well we're still not certain! they read it and even replied to it ( the dum sh*ts! ) but the logs contradict our web filtering software so we have replied to her again with the image still there to make 100% sure!

yes it was tempting to put something along the lines of thanks for opening this please pack yer bags! but just sent a random smiley face saying hello. will see on monday!

chrisjl

785 posts

283 months

Saturday 12th March 2005
quotequote all
billb said:
...but the logs contradict our web filtering software...


If the image is hosted on a www server inside your network, surely there should be only one hit on that file, and that will be the culprit? I suppose there's potential for a default proxy getting in the way, but at least IT'S logs should also only show one hit for that file.

italiano

8,352 posts

233 months

Tuesday 15th March 2005
quotequote all
Just read this and I'm fascinated! Any news?

billb

Original Poster:

3,198 posts

266 months

Tuesday 15th March 2005
quotequote all
well we twice have the person as being on the computer identified on the log at the 2 times the mail was read. The only peculiarity is that we use surf control which is supposed to log every web site the users have been on and this person hasnt been on any mail sites like yahoo or even ones that she could get to one from. So am presuming it just hasnt recorded it - so we will question the person before accusing her totally and see if we can get a confession!! will let u know!

meeja

8,289 posts

249 months

Tuesday 15th March 2005
quotequote all
I'm dying to know what they did in the first place......

billb

Original Poster:

3,198 posts

266 months

Tuesday 15th March 2005
quotequote all
meeja said:
I'm dying to know what they did in the first place......


nothing that u'd think that bad prob! - i work at a school so a pupil sent an abusive mail to a teacher - i like to be able to prove they cannot abuse my system so wanna catch them!

billb

Original Poster:

3,198 posts

266 months

Wednesday 16th March 2005
quotequote all
it was her!! she admitted all! the trap worked well done chaps!!

_Dobbo_

14,393 posts

249 months

Wednesday 16th March 2005
quotequote all
Nice! Let us know when the public flogging is, we'll come and throw tomatoes!

Just kidding. It does feel good when you can play IT god and show people they aren't being as clever as they thought!

chrisjl

785 posts

283 months

Thursday 17th March 2005
quotequote all
Did you get to the bottom of the discrepancy between what the booby-trap was telling you and what the web-filter wasn't?

billb

Original Poster:

3,198 posts

266 months

Thursday 17th March 2005
quotequote all
chrisjl said:
Did you get to the bottom of the discrepancy between what the booby-trap was telling you and what the web-filter wasn't?


no which was a bit annoying - surf control doesnt seem to have logged EVERY site

2 girls have been suspended hope u all feel guilty now!