Compromised?
I recently signed up with a hosting company and started setting up an account on the server (uses ensim). I setup the email for the root@mydomain.com to be forwarded to an email account on my ISP. As a test, I sent an email to root@mydomain.com with the text "Does this work?". The email forwarded correctly.A couple of days later I got a spam-type email on my ISP account with the subject line "RE:Yes it works-U see this right-". The email had several destination addresses in the header, but mine was the only one that appears to be legit.
Could be a big coincidence, but I am not a big believer in coincidence. The text fits too well and I never get spam on that ISP account.
What's up - server hacked, someone inside screwing around?
For what it's worth, here is the message text (edited my address). Any clues?
Received: from mx01.isp.com ([nn.nn.nn.nn]) by mail.isp.com with Microsoft SMTPSVC(5.5.1877.757.75);
Mon, 14 Oct 2002 21:36:28 -0400
Received: from blueprint.fecgz.com ([61.140.189.181])
by mx01.isp.com (8.12.5/8.12.5) with ESMTP id g9F1acgJ018699
for <my email address>; Mon, 14 Oct 2002 21:36:40 -0400 (EDT)
Received: from sd (HXT-PJROEYNQ3LU [211.147.31.137]) by blueprint.fecgz.com with SMTP (Microsoft Exchange Internet Mail Service Version 5.5.2653.13)
id 4G0K4MM4; Thu, 10 Oct 2002 04:29:55 +0800
Message-ID: <000038087767$000019ad$00007204@fg>
To: <postmaster@ti-dream.com>, <kusu@ax-net.co.jp>, <me@my.isp.com>,
<kusu-egy@fancy.ocn.ne.jp>, <motchane@cmla.ens>, <upstate31@aol.com>,
<postmaster@ti-c.com>, <postmaster@thun-hohenstein.org>,
<ghostremovelusa@ghostremovelusa.com>
Cc: <upstartwrg@aol.com>, <motchane@cmla.ens-cachan.fr>, <motch1@fuse.net>,
<postmaster@thustengraff.com>, <kusu2web@yan.ne.jp>,
<ghostrecording@attglobal.net>, <motchane@gomultimedia.fr>, <iurmd@aol.com>
From: 2002biz2biz9961@eudoramail.com
Subject: RE:Yes it works-U see this right- 17420
Date: Thu, 17 Oct 2002 12:24:25 -1900
MIME-Version: 1.0
Content-Type: text/plain;
charset="Windows-1252"
Content-Transfer-Encoding: 7bit
Return-Path: 2002biz2biz9961@eudoramail.com