I have been hacked

My site has had some kind of hacking.  One of my members told me the got a message like the one below with "SPAM-MED" in the header and nothing in the subject sent from my site.  Any idea how they did it?  I have a number of unapproved accounts - could it have been done from one of those?

 

From: California International Business Community [mailto:caltrade@xxx
Sent: Wednesday, August 11, 2010 11:00 AM
To: roger@xxxx
Subject: SPAM-MED:

Quote · 14 Aug 2010

You should edit out those email addresses in your post while you still can

My opinions expressed on this site, in no way represent those of Boonex or Boonex employees.
Quote · 14 Aug 2010

The from line is useless.

Have them send you the full headers of the message. Like so.

Delivered-To: xxxxxxxxxx@gmail.com
Received: by 10.229.1.130 with SMTP id 2cs89124qcf;
Wed, 11 Aug 2010 11:09:19 -0700 (PDT)
Received: by 10.229.87.140 with SMTP id w12mr10020601qcl.125.1281550158909;
Wed, 11 Aug 2010 11:09:18 -0700 (PDT)
Return-Path: <bounce-111538-190241-xxxxxxxxxx=gmail.com@mcsv64.net>
Received: from mcsv64.net (mcsv64.net [72.26.195.67])
by mx.xxxxxx.xxx with ESMTP id l7si913551qck.22.2010.08.11.11.09.17;
Wed, 11 Aug 2010 11:09:17 -0700 (PDT)
Received-SPF: pass (xxxxxx.xxx: domain of bounce-111538-190241-xxxxxxxxxx=gmail.com@mcsv64.net designates 72.26.195.67 as permitted sender) client-ip=72.26.195.67;
Authentication-Results: mx.xxxxxx.xxx; spf=pass (xxxxxx.xxx: domain of bounce-111538-190241-xxxxxxxxxx=gmail.com@mcsv64.net designates 72.26.195.67 as permitted sender) smtp.mail=bounce-111538-190241-xxxxxxxxxx=gmail.com@mcsv64.net; dkim=pass header.i=org=3Dxxxxxx.com@mcsv64.net
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; s=k1; d=mcsv64.net;
h=Subject:From:Reply-To:To:Date:Message-ID:List-Unsubscribe:Sender:Content-Type:MIME-Version; i=org=3Dxxxxxx.com@mcsv64.net;
bh=r9aCAoTzV2RVV5Er4AnFmPUasOY=;
b=N4nHC/AaciU9rWrooyHFTIVCuab9kSLgKUcI2VsVj5ykNKc2LkoL0Dguk3F94zUOGjPqD5eQtc3o
ZPjZOrVNNzFJ83tbUQ5Gbat9PgxyaPh+evZ7cQYyEmW7Cz8u9rnR7/d8CDVs+qI+cUS17N6VjfcV
cCd5Cmj84W3ePNpsayQ=
DomainKey-Signature: a=rsa-sha1; c=nofws; q=dns; s=k1; d=mcsv64.net;
b=MtzxTFRpO1nO4bd/iGOMuFrOxShAloF0OoM6EmYIWiZMCauLFGvhboDM9PflATCLXrZtfszSJFT4
T2F+axbc048ZdbwHdRpo5iQj/prWCCt8NK136uqAr39pSTwQbrpJVCYT49K6w8r7eqGkJfFqucZy
XsAc9Hb4LakCsXM2pGs=;
Received: by mcsv64.net (PowerMTA(TM) v3.5r15) id hcbjkq0ik184 for <xxxxxxxxxx@gmail.com>; Wed, 11 Aug 2010 14:05:38 -0400 (envelope-from <bounce-111538-190241-xxxxxxxxxx=gmail.com@mcsv64.net>)
Subject: Unity Forums Update
From: "xxxxxx" <org@xxxxxx.com>
Reply-To: "xxxxxx" <org@xxxxxx.com>
To: <xxxxxxxxxx@gmail.com>
Date: Wed, 11 Aug 2010 14:05:38 -0400
Message-ID: <52cf23ff174ff9c65c3fc8acbfe36f85c6b.20100811180327@mcsv64.net>
X-Mailer: MailChimp Mailer - **CID6ba13033b2fe36f85c6b**
X-Campaign: mailchimp52cf23ff174ff9c65c3fc8acb.6ba13033b2
X-campaignid: mailchimp52cf23ff174ff9c65c3fc8acb.6ba13033b2
x-im: 38509-6ba13033b2
X-Report-Abuse: Please report abuse for this campaign here: http://www.mailchimp.com/abuse/abuse.phtml?u=52cf23ff174ff9c65c3fc8acb&id=6ba13033b2&e=fe36f85c6b
List-Unsubscribe: <http://xxxxxx.us1.list-manage1.com/unsubscribe?u=52cf23ff174ff9c65c3fc8acb&id=df6f97fde9&e=fe36f85c6b&c=6ba13033b2>
Sender: "xxxxxx" <org=xxxxxx.com@mcsv64.net>
Content-Type: multipart/alternative; boundary="_----------=_MCPart_531198600"
MIME-Version: 1.0



What you are looking for are the Received: lines. Those show you the path the message took to get to the recipient. The last one is the server where the message started.

The problem with from lines is they can be faked. A spammer can put any email address they want in there to make it appear that the mail is from someone else. They can even send a mail to you with your own address in the from line making it appear that you sent it to yourself. The full headers will tell the truth.

My guess is the origin is not from your servers. So you most likely have nothing to worry about. But you should still get the full headers so they can be examined. Your host can tell you if the mail originated from yours or their servers.




https://www.deanbassett.com
Quote · 14 Aug 2010
 
 
Below is the legacy version of the Boonex site, maintained for Dolphin.Pro 7.x support.
The new Dolphin solution is powered by UNA Community Management System.