I've had a reply from Bob. He's taken the time to send a very
detailed reply, which I appreciate. He says:
Hi Kathy,
Thank you for passing this on. Thankfully, this message was NOT
transmitted via any UOA mailing list. We had one incident (on March
3) when a UOA list was hijacked by a virus-infected email. Since
then, we've taken steps
to make sure that won't happen again.
This particular virus-infected email that you've received was sent
directly from a virus infected computer to you and did not pass
through any UOA server. It simply had the address
info@... "spoofed" in the "From" line.
In all likelihood, the owner of the infected computer is someone who
knows you (or at least, has your email address) and has also visited
the UOA website (therefore, had the address info@... on his/her
computer).
Note: I use the email address mainly for mailing lists. There are
very few personal emails.
About harvesting and spoofing: "Harvesting" refers to software that
scans the web for the specific purpose of extracting email addresses.
Spammers often obtain addresses this way. On the UOAsite, I've tried
to protect email addresses from harvesting by using a JavaScript
technique; see:
http://www.uoa.org/discussion/genboard0312/messages/815.html
"Spoofing" refers to forging the sender of an email message so it
looks like it was sent by somebody different than the real sender.
Spam emails often include forged senders. Most current viruses also
do email spoofing. When one of these viruses infects a computer, it
scans numerous files on the infected computer to locate email
addresses. Then, of the addresses it finds, it picks them randomly in
pairs, sending emails with one address on the "To" line and another
on the "From" line. In this case, it sent an
email to you with info@... on the "From" line.
From the details you've provided, it appears that this particular
virus-infected email was sent from IP address 81.153.48.238 which
resolves to the longer form host81-153-48-238.range81-
153.btcentralplus.com and appears to belong to an ISP in the UK.
Thus, the infected computer seems to
belong to a BT (British Telecom) customer. As I said, the message was
sent directly from that computer to you, and did not pass through any
UOA server.
Best regards,
Bob