(The quickest way to register)

Forum

Dear visitor! The webpage is only available in English. We're sorry for the inconvenience.
  1. User picture
    • tinfoil on Tue 03 Nov 2009
    • 05:56:19 PM UTC

    google.com email address possibly compromised.

    Today, I received a spam email. At, first, I ignored it; I only read through my spam emails to report the links that I find. Then I noticed the sender. "Google-Admin ". That was copy-and-pasted from the email; it is exactly "@google.com", not "g0ogle.com", "9oogle.com", "googIe.com" or any other possible similar domain.

    While I am confident that admin.official@google.com is not Google's administrator's email address- it is too obvious- I am also confident that Google never allowed the public @google.com email addresses. As such, I fear for Google;s security. Is this a breach, or is this just a cloaked email address?

    Full message is as follows (headers etc. included).

    From Google-Admin Sun Nov 1 20:59:24 2009
    X-Apparently-To: ...@btinternet.com via 217.146.188.133; Sun, 01 Nov 2009 20:59:27 +0000
    Return-Path:
    X-YahooFilteredBulk: 200.49.175.189
    X-YMailISG: Y_HVLGQWLDvqRAcUgZroVTvkx1QRfjBf9cn0z04meyEvt_PIOPuuxqVh2z2TwT7WeL.L3k9Le9_Xinv0CkSBh4UdzyEhsxmfcQ2Cz637dSWrK0mAZunzrjK7uy_8MgayzVSwR6kCK08.tjsAIv3mo64x0gHPBIETU3YPxaNPRrNPm1IW9BQECpGuO_tHQqvYFA42zrbDZHFpxDkF4RPAdYe4gU44jFomfL8A1cbZKzNDT29D5lUQ8fwg_PIXmpJDwn_0raDVvqpVWCP29_Qrj6HssfF74Nwj1caywSRDV7k-
    X-Originating-IP: [200.49.175.189]
    Authentication-Results: mta840.mail.ukl.yahoo.com from=google.com; domainkeys=neutral (no sig); from=google.com; dkim=neutral (no sig)
    Received: from 200.49.175.189 (EHLO srvmail01.clt.com.gt) (200.49.175.189)
    by mta840.mail.ukl.yahoo.com with SMTP; Sun, 01 Nov 2009 20:59:27 +0000
    Received: from david (dslb-088-076-214-243.pools.arcor-ip.net [88.76.214.243])
    (Authenticated sender: david)
    by srvmail01.clt.com.gt (Postfix) with ESMTP id 015361980961;
    Sun, 1 Nov 2009 14:26:34 -0600 (CST)
    Reply-To:
    From: "Google-Admin"
    Subject: Hello!
    Date: Sun, 1 Nov 2009 21:59:24 +0100
    MIME-Version: 1.0
    Content-Type: text/html;
    charset="Windows-1251"
    Content-Transfer-Encoding: 7bit
    X-Priority: 3
    X-MSMail-Priority: Normal
    X-Mailer: Microsoft Outlook Express 6.00.2600.0000
    X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
    Message-Id: <20091101202635.015361980961@srvmail01.clt.com.gt>
    To: undisclosed-recipients:;
    Content-Length: 1872

    A short while after, another arrived:

    From Google-Admin Mon Nov 2 23:48:10 2009
    X-Apparently-To: ...@btinternet.com via 217.146.188.127; Mon, 02 Nov 2009 23:48:16 +0000
    Return-Path:
    X-YahooFilteredBulk: 199.88.112.10
    X-YMailISG: ZgRcUE4WLDsV3ZyCw84mZMomGur5sECtchW3HlK1p2kH6UMLGWaKlwKiu74eXcxqQohQN1Z_NoHSjm0QgcrL5CzuwLFNRUtH5XoI2JHADEwoLq6aNQJkdjt0h1tYv30p_RLHRsHobX47es5ZZl45JBOSxHgmwOtQFAF96Sb3PmjSUj0_bMaSW_wpSxtnuJ6HiWSNyPF5ySf7ZI0rHBWG9G49I9kOseVVS3Ty69d_qES5rinIn08y7Gnngq.8x1a7AAohpIt3w2b0lneOQb5YZ9WNzU.NWu7ex.PPm5QYhL5q0kXGQ4UEtCL0WG5T3nTHR_J3_kd5Rf.V9mqUxzIRbj69J3ELbIO8gzVWZIBhAdM-
    X-Originating-IP: [199.88.112.10]
    Authentication-Results: mta823.mail.ird.yahoo.com from=google.com; domainkeys=neutral (no sig); from=google.com; dkim=neutral (no sig)
    Received: from 199.88.112.10 (EHLO marin.marin.k12.ca.us) (199.88.112.10)
    by mta823.mail.ird.yahoo.com with SMTP; Mon, 02 Nov 2009 23:48:16 +0000
    Received: from User [88.76.214.243] by marin.marin.k12.ca.us with ESMTP
    (SMTPD-9.21) id AFB122C0; Mon, 02 Nov 2009 15:48:01 -0800
    Reply-To:
    From: "Google-Admin"
    Subject: Hello !
    Date: Tue, 3 Nov 2009 00:48:10 +0100
    MIME-Version: 1.0
    Content-Type: text/html;
    charset="Windows-1251"
    Content-Transfer-Encoding: 7bit
    X-Priority: 3
    X-MSMail-Priority: Normal
    X-Mailer: Microsoft Outlook Express 6.00.2600.0000
    X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
    Message-Id: <200911021548379.SM10724@User>
    X-Declude-Sender: admin.official@google.com [88.76.214.243]
    X-Declude-Spoolname: D6faa030b00008570.smd
    X-Declude-RefID:
    X-Declude-Note: Scanned by Declude 4.3.46 (http://www.declude.com/x-note.htm) for spam.
    X-Declude-Scan: Score [0] at 15:48:08 on 02 Nov 2009
    X-Declude-Tests: Whitelisted
    X-Country-Chain:
    Content-Length: 1872

    Edit: removed the recipient's email address before more spambots find it. -- Sami

    Inactive.

Comments:

  1. User picture
    • Sami on Tue 03 Nov 2009
    • 06:11:57 PM UTC

    Re: google.com email address possibly compromised.

    I don't see any evidence of a google.com account being involved. It's trivial to forge the sender's address in an email.

    • User picture
      • tinfoil on Tue 03 Nov 2009
      • 06:18:15 PM UTC

      Sorry; I jumped to

      Sorry; I jumped to conclusions at the time. Looking at it now, it's quite obvious that it's forged. Please forgive me.