Technical advice

用戶圖片

google.com email address possibly compromised.

Today, I received a spam email. At, first, I ignored it; I only read through my spam emails to report the links that I find. Then I noticed the sender. "Google-Admin ". That was copy-and-pasted from the email; it is exactly "@google.com", not "g0ogle.com", "9oogle.com", "googIe.com" or any other possible similar domain.

While I am confident that admin.official@google.com is not Google's administrator's email address- it is too obvious- I am also confident that Google never allowed the public @google.com email addresses. As such, I fear for Google;s security. Is this a breach, or is this just a cloaked email address?

Full message is as follows (headers etc. included).

From Google-Admin Sun Nov 1 20:59:24 2009
X-Apparently-To: ...@btinternet.com via 217.146.188.133; Sun, 01 Nov 2009 20:59:27 +0000
Return-Path:
X-YahooFilteredBulk: 200.49.175.189
X-YMailISG: Y_HVLGQWLDvqRAcUgZroVTvkx1QRfjBf9cn0z04meyEvt_PIOPuuxqVh2z2TwT7WeL.L3k9Le9_Xinv0CkSBh4UdzyEhsxmfcQ2Cz637dSWrK0mAZunzrjK7uy_8MgayzVSwR6kCK08.tjsAIv3mo64x0gHPBIETU3YPxaNPRrNPm1IW9BQECpGuO_tHQqvYFA42zrbDZHFpxDkF4RPAdYe4gU44jFomfL8A1cbZKzNDT29D5lUQ8fwg_PIXmpJDwn_0raDVvqpVWCP29_Qrj6HssfF74Nwj1caywSRDV7k-
X-Originating-IP: [200.49.175.189]
Authentication-Results: mta840.mail.ukl.yahoo.com from=google.com; domainkeys=neutral (no sig); from=google.com; dkim=neutral (no sig)
Received: from 200.49.175.189 (EHLO srvmail01.clt.com.gt) (200.49.175.189)
by mta840.mail.ukl.yahoo.com with SMTP; Sun, 01 Nov 2009 20:59:27 +0000
Received: from david (dslb-088-076-214-243.pools.arcor-ip.net [88.76.214.243])
(Authenticated sender: david)
by srvmail01.clt.com.gt (Postfix) with ESMTP id 015361980961;
Sun, 1 Nov 2009 14:26:34 -0600 (CST)
Reply-To:
From: "Google-Admin"
Subject: Hello!
Date: Sun, 1 Nov 2009 21:59:24 +0100
MIME-Version: 1.0
Content-Type: text/html;
charset="Windows-1251"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
Message-Id: <20091101202635.015361980961@srvmail01.clt.com.gt>
To: undisclosed-recipients:;
Content-Length: 1872

A short while after, another arrived:

From Google-Admin Mon Nov 2 23:48:10 2009
X-Apparently-To: ...@btinternet.com via 217.146.188.127; Mon, 02 Nov 2009 23:48:16 +0000
Return-Path:
X-YahooFilteredBulk: 199.88.112.10
X-YMailISG: ZgRcUE4WLDsV3ZyCw84mZMomGur5sECtchW3HlK1p2kH6UMLGWaKlwKiu74eXcxqQohQN1Z_NoHSjm0QgcrL5CzuwLFNRUtH5XoI2JHADEwoLq6aNQJkdjt0h1tYv30p_RLHRsHobX47es5ZZl45JBOSxHgmwOtQFAF96Sb3PmjSUj0_bMaSW_wpSxtnuJ6HiWSNyPF5ySf7ZI0rHBWG9G49I9kOseVVS3Ty69d_qES5rinIn08y7Gnngq.8x1a7AAohpIt3w2b0lneOQb5YZ9WNzU.NWu7ex.PPm5QYhL5q0kXGQ4UEtCL0WG5T3nTHR_J3_kd5Rf.V9mqUxzIRbj69J3ELbIO8gzVWZIBhAdM-
X-Originating-IP: [199.88.112.10]
Authentication-Results: mta823.mail.ird.yahoo.com from=google.com; domainkeys=neutral (no sig); from=google.com; dkim=neutral (no sig)
Received: from 199.88.112.10 (EHLO marin.marin.k12.ca.us) (199.88.112.10)
by mta823.mail.ird.yahoo.com with SMTP; Mon, 02 Nov 2009 23:48:16 +0000
Received: from User [88.76.214.243] by marin.marin.k12.ca.us with ESMTP
(SMTPD-9.21) id AFB122C0; Mon, 02 Nov 2009 15:48:01 -0800
Reply-To:
From: "Google-Admin"
Subject: Hello !
Date: Tue, 3 Nov 2009 00:48:10 +0100
MIME-Version: 1.0
Content-Type: text/html;
charset="Windows-1251"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
Message-Id: <200911021548379.SM10724@User>
X-Declude-Sender: admin.official@google.com [88.76.214.243]
X-Declude-Spoolname: D6faa030b00008570.smd
X-Declude-RefID:
X-Declude-Note: Scanned by Declude 4.3.46 (http://www.declude.com/x-note.htm) for spam.
X-Declude-Scan: Score [0] at 15:48:08 on 02 Nov 2009
X-Declude-Tests: Whitelisted
X-Country-Chain:
Content-Length: 1872

Edit: removed the recipient's email address before more spambots find it. -- Sami

用戶圖片

Re: google.com email address possibly compromised.

I don't see any evidence of a google.com account being involved. It's trivial to forge the sender's address in an email.

用戶圖片

Sorry; I jumped to

Sorry; I jumped to conclusions at the time. Looking at it now, it's quite obvious that it's forged. Please forgive me.

© WOT Services 專利申請中