LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > SUSE / openSUSE
User Name
Password
SUSE / openSUSE This Forum is for the discussion of Suse Linux.

Notices


Reply
  Search this Thread
Old 07-06-2006, 04:10 PM   #1
agentchange
Member
 
Registered: May 2006
Distribution: Ubuntu 8.04
Posts: 132

Rep: Reputation: 15
Hijacked email account


I just installed Suse a few weeks ago and I'm still something of a newbie. I started getting strange messages showing up in my Yahoo email account, such as a returned email because it was detected as spam, and a delivery failure notice, as well, both of which I never sent. One of them is in the French language, where I hear that Suse is very popular. It looks like someone has access to my email account and is using it to send spam from, though there are no messages showing up in my Sent box. I could possibly just change my password, but then I am wondering if maybe someone can somehow be skimming or hacking my computer to find out my passwords.
 
Old 07-06-2006, 04:48 PM   #2
Brian1
LQ Guru
 
Registered: Jan 2003
Location: Seymour, Indiana
Distribution: Distribution: RHEL 5 with Pieces of this and that. Kernel 2.6.23.1, KDE 3.5.8 and KDE 4.0 beta, Plu
Posts: 5,700

Rep: Reputation: 65
It is possible if you use features like save passwords or remeber passwords and so on.
First thing to do is login to the yahoo account and change the password to a stronger type of one. Longer password, alphanumeric characters, no standard words.

I would check your logs to see if any unknown logins have happen. Also change your password on your suse account and root account while your at it. Check for unusally or new user accounts on system. Look at /etc/passwd file and see if others may have 0 level which root normally has. Not sure where users start in SUSE. Most Redhat clones users start at 500 on for UID. Check groups as well. This is a start many other ways in if some services are active.

Is this connected directly to a cable or dsl modem?
If so is there a firewall up?
If not get one up.
Or better yet get a firewall cable/dsl router and use that between comptuer and modem.

Brian1
 
Old 07-06-2006, 05:36 PM   #3
manishsingh4u
Member
 
Registered: Oct 2005
Location: Bhopal, India
Distribution: RHEL 6
Posts: 422

Rep: Reputation: 30
This happened to one of my class mates yahoo id. We used to get porn stuff related mails from his email id at our yahoogroups id. And he never sent those mails. The cause is still unknown as now we are not getting any such mails.
 
Old 07-06-2006, 05:43 PM   #4
manishsingh4u
Member
 
Registered: Oct 2005
Location: Bhopal, India
Distribution: RHEL 6
Posts: 422

Rep: Reputation: 30
1) Disable ssh or telnet service or limit it to any specific user/ipaddress if u need it. (and if u have it enabled)
2( Chabge all your local passwords eg (<hxJ37*k?>) is considered as a strong password. The length matters too as they mostly use brute force attach to crack passwrds (Once my local password was cracked by someone through ssh)
3) Change your email password from some other PC in case ur keys might be logged.
4) Still if this happens, you should report this to the email service provider.

Last edited by manishsingh4u; 07-07-2006 at 04:06 AM.
 
Old 07-06-2006, 11:09 PM   #5
agentchange
Member
 
Registered: May 2006
Distribution: Ubuntu 8.04
Posts: 132

Original Poster
Rep: Reputation: 15
It is hooked up directly to a cable modem, no router. I see a couple of firewalls installed, Susefirewall2 and yast2-firewall, though I am not really sure what exactly they cover. I found the one in Yast that seems to probably be up and running, but it doesn't look like there is much to configure.

I am also wondering if perhaps they are just using my email address as a return email address. I have used one of these email programs before, and you can plug in whatever return email address you want. If that is the case, I find it odd that I only received a couple of these. I am going to change my password and contact yahoo and see what they have to say.
 
Old 07-07-2006, 11:20 AM   #6
dasy2k1
Member
 
Registered: Oct 2005
Location: 127.0.0.1
Distribution: Manjaro
Posts: 963

Rep: Reputation: 36
if you have an old computer lying around (and it can be extramly old i use a celeron 400 with a 2.5GB HDD) i woul recoment IPCOP if you dont want to fork ouit the money for a router

download it from www.ipcop.org
forum on ipcops.com

but a cheap NAT router will take up less space/ make less noise
 
Old 07-07-2006, 04:09 PM   #7
Brian1
LQ Guru
 
Registered: Jan 2003
Location: Seymour, Indiana
Distribution: Distribution: RHEL 5 with Pieces of this and that. Kernel 2.6.23.1, KDE 3.5.8 and KDE 4.0 beta, Plu
Posts: 5,700

Rep: Reputation: 65
If you are unsure about a firewall then I would go get a cheap firewall router no wireless and put that on the modem and then connect computer to router. Best cheapest, quickest way to get secure.

Brian1
 
Old 07-08-2006, 04:18 PM   #8
dasy2k1
Member
 
Registered: Oct 2005
Location: 127.0.0.1
Distribution: Manjaro
Posts: 963

Rep: Reputation: 36
i agree with brian,
though the chances are that you yahoo account has been compramised at the server side rather than at your computer...
ny hotmail account was totlly compramised once by some idiots who managed to crack the encryption uised by MSN
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
cyrus email account linux account nobu Linux - Enterprise 0 10-31-2005 03:16 AM
using multiple email programs for one email account kshaffer Linux - Software 1 01-07-2005 05:00 PM
Creating A Second Email Address For Email Account On Sendmail treedstang Linux - Software 1 04-27-2004 10:31 PM
Email account ... JMK Linux - Newbie 2 03-12-2004 04:54 AM
Sharing a POP email account kiTz Linux - General 1 12-21-2003 08:52 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > SUSE / openSUSE

All times are GMT -5. The time now is 08:16 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration