Re: Lighthearted technical question

1

"Practical joke" s/b "bank fraud"


Posted by: DaveL | Link to this comment | 04-16-07 3:11 PM
horizontal rule
2

Yeah, sure.


Posted by: Beefo Meaty | Link to this comment | 04-16-07 3:12 PM
horizontal rule
3

Would this email purport to be from an imaginary person, or a real-life person from whom the recipient might expect to receive an email?


Posted by: sam k | Link to this comment | 04-16-07 3:13 PM
horizontal rule
4

Does the apparent email address need to be the actual address? If not, you could just make "saul.kripke@gmail.com" or something, and put the appropriate name in the Display Name field.


Posted by: Matt F | Link to this comment | 04-16-07 3:14 PM
horizontal rule
5

P.S. I assume you don't actually need to fake the headers. That's not hard either, but it requires either some hacker warez or some knowledge of SMTP syntax. Seems a little complicated for a prank.


Posted by: Beefo Meaty | Link to this comment | 04-16-07 3:16 PM
horizontal rule
6

You're going to have to walk him through it more than you did in 2, Tweety.


Posted by: ogged | Link to this comment | 04-16-07 3:19 PM
horizontal rule
7

Yeah, the easiest way to do this would be to simply create a new e-mail account with the name of your choice. It's not like Hotmail or gmail require a social security number with an account. Any replies to that e-mail will then go to that name, or in other words, to you. It should work fine unless you can't be seen checking an e-mail account that isn't your usual one for some strange reason.


Posted by: Cyrus | Link to this comment | 04-16-07 3:21 PM
horizontal rule
8

purports to be from someone else

Just from someone else, or from some specific other email address?


Posted by: ogged | Link to this comment | 04-16-07 3:23 PM
horizontal rule
9

Um, for Outlook Express, click on my second link, search for "How Spoofing Works," and then follow the instructions.

In Apple Mail, create a new account or, using your own, change the "Description" "Email Address" and "Full Name" fields to whatever you want, while leaving Incoming Mail Server, Username, and Password the same.

In any other client you'll have to figure it out for yourself.


Posted by: Beefo Meaty | Link to this comment | 04-16-07 3:25 PM
horizontal rule
10

Windows XP:
Click on Start/Run
Type "cmd" and press enter
Type "telnet mail.hotmail.com 25" and press enter
Type "MAIL FROM: whoever@youwanttobe.com" and press enter
Type "RCPT TO: whoever@youwanttosenditto.com" and press enter
Type "DATA" and press enter
Type "Subject: This is my subject" and press enter
Now write whatever you want. When you're done writing, type "." without the quotations and press enter. The email will be sent.


Posted by: Yeho | Link to this comment | 04-16-07 3:34 PM
horizontal rule
11

That is, type "." on a line all by itself.


Posted by: Yeho | Link to this comment | 04-16-07 3:35 PM
horizontal rule
12

10 what I didn't want to explain in 5.


Posted by: Beefo Meaty | Link to this comment | 04-16-07 3:40 PM
horizontal rule
13

Okay, I just reread your original question and there is actually no real way to do what you're asking. The method I (and the one Beefo Meaty) gave you will send them an email in which the "from" field contains, say, "elpresidente@whitehouse.gov". When the person responds, the email program will only read the "from" or "reply-to" (or "cc:") fields to determine to whom to reply, so in this case "elpresidente@whitehouse.gov". There is no way to trick the email program so that it responds to you rather than the spoofed sender. So, yeah, the best way would be to just create a fake account at yahoo or hotmail or something. But then, obviously, you wouldn't be able to spoof "elpresidente@whitehouse.gov".


Posted by: Yeho | Link to this comment | 04-16-07 3:40 PM
horizontal rule
14

But you could spoof the from field and then have the response mail sent to Ima_Fake@gmail.com, which would be pretty plausible.


Posted by: Beefo Meaty | Link to this comment | 04-16-07 3:41 PM
horizontal rule
15

er set the reply-to field, that is.


Posted by: Beefo Meaty | Link to this comment | 04-16-07 3:42 PM
horizontal rule
16

To: Alberto Gonzales
From: Karl Rove
Subject: Re: USAs

For practical joke purposes I need to send an email that purports to be from someone else. Ideally, a response to that email would go to me, not the listed "from" or "reply to" address. Is this easy?


Posted by: Armsmasher | Link to this comment | 04-16-07 3:42 PM
horizontal rule
17

14,15: That's certainly the best option if you want to spoof a non-yahoo or -hotmail address. It does run the risk of either a pop-up saying something like "Do you want to reply to the 'from' address or the 'reply-to' address," or else the person may just see that the reply-to address is "fontana_labs@ilovepuppies.com" instead of "elpresidente@whitehouse.gov". A calculated risk, I suppose.


Posted by: Yeho | Link to this comment | 04-16-07 3:50 PM
horizontal rule
18

17: It would help to know the victim's e-mail client.


Posted by: Beefo Meaty | Link to this comment | 04-16-07 3:52 PM
horizontal rule
19

If you happen to have wheel access to either the sending or receiving machines, or one guaranteed to be in the path, then anything is possible. Otherwise, at best your IP's won't match up. It's true that the recievers client and how carefully you want this prank to hold up matter.


Posted by: soubzriquet | Link to this comment | 04-16-07 3:58 PM
horizontal rule
20

19: `almost anything is possible' really. you can't make these things watertight


Posted by: soubzriquet | Link to this comment | 04-16-07 3:58 PM
horizontal rule
21

This all reminds me of when I did something quite mean in middle school. A woman with little to no computer knowledge whatsoever was put in charge of the middle school computer lab. She was actually quite nice, but just absolutely clueless. One day, for reasons that escape me (probably because it was simply out of meanness), I spoofed an email message to her from the principal telling her that she needed to see me (the principal) about her losing her job. I knew it wouldn't hold water the instant she set foot inside the principal's office, but I also knew it would scare the living hell out of her for a period of time. This was also in the mid-nineties when the full power of intarweb trickery was still somewhat under the radar, so in retrospect I imagine that she was pretty shocked.

No punchline to this story, by the way. I am still deeply ashamed at being so callous for no reason to someone who didn't deserve it.


Posted by: Yeho | Link to this comment | 04-16-07 3:59 PM
horizontal rule
22

19: That's a ginormous "if".


Posted by: Yeho | Link to this comment | 04-16-07 4:00 PM
horizontal rule
23

22: well, yes. My point was more that *unless* you can do this, the spoofs are all very easily found.

Actually, I missed a case. If you know the IP of a machine in the path, know the network topology, and have a machine in the network that you are either lucky with the routing location of can change that, then you can probably do it to.


Posted by: soubzriquet | Link to this comment | 04-16-07 4:03 PM
horizontal rule
24

Yeah, indeed. I sort of figured 19 was not a likely thing. Neither did I figure it was a likely thing that FL would have console access to the mail server, although that too would be helpful.

19 also presupposes *nix. If it's Exchange it's a different story.


Posted by: Beefo Meaty | Link to this comment | 04-16-07 4:04 PM
horizontal rule
25

23: There's loads of ways to do it if you're actually down to be hacking networks. Lack of pre-existing wheel group access or knowledge of network topology aren't barriers if you're motivated.

But that's fairly motivated for somebody who hasn't done this before.


Posted by: Beefo Meaty | Link to this comment | 04-16-07 4:05 PM
horizontal rule
26

I think we should turn FL's little prank into a full-fledged "Sneakers"-style tiger team assault. I want to be River Phoenix.


Posted by: Yeho | Link to this comment | 04-16-07 4:07 PM
horizontal rule
27

You're going to post the email and response on the blog, right?


Posted by: bitchphd | Link to this comment | 04-16-07 4:09 PM
horizontal rule
28

26: No deal unless I get to be Sidney Poitier. Pretty slim pickings otherwise.


Posted by: Beefo Meaty | Link to this comment | 04-16-07 4:13 PM
horizontal rule
29

I wouldn't call Robert Redford, David Strathairn, and Dan Aykroyd slim pickings. I mean, come on, it's Dan Aykroyd. Greatest actor of his generation. Ghostbusters, Grosse Pointe Blank, Sgt. Bilko, Coneheads, need I say more?


Posted by: Yeho | Link to this comment | 04-16-07 4:20 PM
horizontal rule
30

He's not slim, no.

I refer also to the fact that he was playing the conspiracy-theory minded comic relief, a role I embody well enough in my normal life to not aspire to it.


Posted by: Beefo Meaty | Link to this comment | 04-16-07 4:23 PM
horizontal rule
31

Re: Update.

You really aren't a very nice person at all, FL. (Okay, it would have been hilarious. But really not nice.)


Posted by: LizardBreath | Link to this comment | 04-16-07 7:58 PM
horizontal rule
32

32: Also, B is shrill.


Posted by: DaveL | Link to this comment | 04-16-07 8:01 PM
horizontal rule
33

There are still other, equally funny pranks you could pull. You could send a fake email announcing that a close relative had died. Perhaps you want to fake a cancer diagnosis next.


Posted by: rob helpy-chalk | Link to this comment | 04-16-07 8:04 PM
horizontal rule
34

Hott coed sexx0r! Way better than a practical joke.


Posted by: mrh | Link to this comment | 04-16-07 10:22 PM
horizontal rule
35

Why am I shrill? In the past, I've done the same thing as Labs's colleague.


Posted by: bitchphd | Link to this comment | 04-16-07 10:33 PM
horizontal rule
36

You guys aren't obligated to kill fun that's already dead, you know.


Posted by: ogged | Link to this comment | 04-16-07 10:44 PM
horizontal rule
37

32: You misspelled "strident".


Posted by: Hamilton Lovecraft | Link to this comment | 04-17-07 2:01 AM
horizontal rule
38

Let's spoof B.


Posted by: John Emerson | Link to this comment | 04-17-07 5:38 AM
horizontal rule
39

Why am I shrill?

By definition. Or something.


Posted by: apostropher | Link to this comment | 04-17-07 10:18 AM
horizontal rule
40

This story is just sixteen different kinds of wrong. I mean, what kind of school do you teach at, Labs?


Posted by: slolernr | Link to this comment | 04-17-07 2:27 PM
horizontal rule