Welcome to HBH! If you had an account on hellboundhacker.org you will need to reset your password using the Lost Password system before you will be able to login.

Self distruction E-mail


ghost's Avatar
0 0

i need to send an email somewhere and i want to know the prosses it take to make it self disdruct after the reader opening it, also any othe neat tricks.

Im using a web site that is doning it for me but i dont know if it is the best one, i would also want to see if anyone could help me with some good web sites???

dut i wish do do it manually..

thanx for any help


ghost's Avatar
0 0

First, learn to speak PROPER English, second it's not a good idea to use email for sensitive information in the first place. They can't "self-destruct" or any garbage like that. Why? Because it's commercial and the security is high enough that it would be stupid to try and hack such a thing, javascript is disabled(unless a new PoC just came out) and various other things as well.

Put simply don't do something stupid


ghost's Avatar
0 0

You can start sending tracked emails immediately by simply adding: .self-destructing-email.com to the end of your recipients email address.

It works, i have tried it my self… ohh and also i work for the government and thy constantly do that wehere they self distruct.

ohh thant for some of good information tyou gave me but i beleave you are wrong.i the computer world anything is possiable.. PLEASE BE NICE TO MY RESPONCE i really tried asking in a frendly matter.

I look forwark for hbh help.. ohh i have also donated money to HBH

I need home simple positive help and not negative. ohh bout my spelling… I my a high ranck at my university and have two BA. for science and three AS. so im pretty smart with spelling and logical thinking. ohh im also top 30% of the smatest person there with executivr athotity.

BUT IALWAYS COME TO HBH FOR HELP AND I HAVE BEEN FOR THE PAST THEE YEARS


ghost's Avatar
0 0

regedit, shut the fuck up…

if you say your smart then why don't you prove it?

what school do you goto, DeVry?


Futility's Avatar
:(
80 120

regedit wrote: ohh bout my spelling… I my a high ranck at my university and have two BA. for science and three AS. so im pretty smart with spelling and logical thinking. ohh im also top 30% of the smatest person there with executivr athotity.

…Are you kidding me? You can't even spell 'smartest' right and you have a fucking spell checker right in front of you. If you really are in the top 30%, then your entire school must be filled with idiots.

Overall, this has to be a joke. I honestly can't see any circumstance where someone could be this…this…the English vocabulary doesn't even have a word to describe what this is.


ghost's Avatar
0 0

Futility wrote:

…Are you kidding me? You can't even spell 'smartest' right and you have a fucking spell checker right in front of you. If you really are in the top 30%, then your entire school must be filled with idiots.

Overall, this has to be a joke. I honestly can't see any circumstance where someone could be this…this…the English vocabulary doesn't even have a word to describe what this is.

i concur


ynori7's Avatar
Future Emperor of Earth
0 0

regedit wrote: I need home simple positive help and not negative. ohh bout my spelling… I my a high ranck at my university and have two BA. for science and three AS. so im pretty smart with spelling and logical thinking. ohh im also top 30% of the smatest person there with executivr athotity.

i didnt mind your poor spelling and grammar until you went and and said this. if english is your first language, the fact that you made at least 10 spelling/grammar errors in your paragraph defending your spelling abilities is pathetic. if english is not your first language you should have just said so and you would have been forgiven.

i especially find this line amusing:

ohh im also top 30% of the smatest person there with executivr athotity. not only is your spelling/grammar terrible in that line, but you come off as a pompous ass. you should fix that, it will help you in life.


ghost's Avatar
0 0

well thnx for been nice… wow this was greatly helpfull :ninja:


Futility's Avatar
:(
80 120

regedit wrote: well thnx for been nice… wow this was greatly helpfull :ninja:

What, you want us to feel sorry for you? Maybe if you posted your question/reply in some sort of manageable language we could have helped you. I agree with ynori7 on this one, you came off as a pompous asshole. Maybe if you spent less time bragging and more time thinking your posts through you would have gotten something helpful out of this. At least now you know what not to do, so next time you might actually not waste everyone's time.


ghost's Avatar
0 0

so is anyone willing to help…

HELLO THIS IS A WEBPAGE WHERE PROPLE COME together and share information,,,,, :ninja:


ghost's Avatar
0 0

idc what that idiot is askin, just as a side note its not impossible to make an email self destruct or crap like that, as a matter of fact there is a possible csrf exploit in yahoo's old email system (dont know about the most recent one) that u could use if u play around wif it enough. ;) I played around a bit in summer and i was too lazy to go on and i was like meh fuck it…anyways…so yeah dont be so sure about possibilities yet :happy:


mikispag's Avatar
=> Penguin in black <=
0 0

I read from the site posted by regedit (http://www.self-destructing-email.com/self-destructing-email/about.asp):

Self-Destructing-Email will endeavour to provide the following in your tracking reports:

* Date and time opened
* Location of recipient (per their ISP city /town)
* Map of location (available on paid subscriptions)
* Recipients IP address
* Apparent email address of opening (if available)
* Referrer details (ie; if accessed via web mail etc)
* URL clicks
* How long the email was read for
* How many times your email was opened
* If your email was forwarded, or opened on a different computer

They also offer a Live Sample Report.

Let me say that honestly it looks quite strange to me. In my opinion it's possible to gather information such as "How long the email was read for", or forwarding information only using Javascript or making the reader load external images/scripts, which is commonly not allowed by every serious webmail or mail client.

Very, very, very strange indeed. Don't trust them.


ghost's Avatar
0 0

**regedit wrote:**I my a high ranck at my university and have two BA. for science and three AS. so im pretty smart with spelling and logical thinking. ohh im also top 30% of the smatest person there with executivr athotity.

You go to some sort of school for 'special' people? :happy:


Uber0n's Avatar
Member
0 0

If you absolutely want the email to be deleted when a person opens it, you should try to find a CSRF vulnerability in your target's mail client. The only client I'm experienced with this kind of exploit in is the Novell GroupWise web based mail system. So go hunting for a XSS and make the email load a CSRF ;)

EDIT: That self-destructing-email.com site has some serious security issues, I wouldn't trust them at all :vamp:


mikispag's Avatar
=> Penguin in black <=
0 0

Uber0n wrote: That self-destructing-email.com site has some serious security issues, I wouldn't trust them at all :vamp:

LOL :D


Mr_Cheese's Avatar
0 1

if you want the email to be deleted when opened. have all the text in an image. host the image somewhere, then have an .htaccess in the folder so once the image is reviewed, its over written.

that would work. however some security settings you have to click "allow images" when reading hte email, so the text wont appear straight away.


Uber0n's Avatar
Member
0 0

Really good idea Cheese, I never would've thought of that :p


ghost's Avatar
0 0

The last thinking there, with a image wasnt that bad idea. It was actually realistic. And just like everyone else here, don't trust self-destructing-email.com, its all loaded with crap. I am btw, going to test it, with a temp. email that I just made, hbh.mailuser1@gmail.com which is going to send an "self-destruction-email" to hbh.mailuser2@gmail.com.

Test Results: Well, this will come as a shock for many. But it is working. Not maybe in that way everyone though. But what happens is, you register your email. Get some information shit, how to, blah blah blah. And then I sent an email from my registered user (hbh.mailuser1@gmail.com) to hbh.mailuser2@gmail.com(hbh.mailuser2@gmail.com.self-destructing-email.com). What happent was that hbh.mailuser2 got an email from self-destructing-email.com with an link. Click it, and there is the msg. If you click anywhere, the thing disperse and cannot be viewed again. And then my registered user, hbh.mailuser1 got an email with the information they say they give you.


ghost's Avatar
0 0

Want to test postdata/restore session while your at it? Something like "print screen" would also capture some data. I was going to look into a graphics card question.Could you make sure they were using an anonymous browser like Browzar or Torrify?

Just have the message in an attachment, and have a logic bomb + timer that formats the C drive. Then they wont care about your stupid email …Or maybe they will care a lot more =P

PS: If it is the kind of thing you don't want them reading twice, It is probably the kind of thing where you don't want them to know you sent it too. So think about that too.

PPS: you said you work for the gov, job title? what do you do?


mikispag's Avatar
=> Penguin in black <=
0 0

Syntaxe wrote: Test Results: Well, this will come as a shock for many. But it is working. Not maybe in that way everyone though. But what happens is, you register your email. Get some information shit, how to, blah blah blah. And then I sent an email from my registered user (hbh.mailuser1@gmail.com) to hbh.mailuser2@gmail.com(hbh.mailuser2@gmail.com.self-destructing-email.com). What happent was that hbh.mailuser2 got an email from self-destructing-email.com with an link. Click it, and there is the msg. If you click anywhere, the thing disperse and cannot be viewed again. And then my registered user, hbh.mailuser1 got an email with the information they say they give you.

Oh my God! :D Super, super, super scam then :)


ghost's Avatar
0 0

You get what you are asking, but not the way you think xD Whats the point of sending someone a link. Even I can do that -_-

Don't use self-destructing-email.com, if you are going to send someone a link with a msg, then you can most possibly make it allot better by your self xD


spyware's Avatar
Banned
0 0

How do you mean, shock? It works exactly as I suggested it could work.


ghost's Avatar
0 0

spyware wrote: Send a link, something like:

www.website.com/secretmessage.php?activate=supercodehere

When someone clicks the link the PHP file checks whether the supercode is given, if it is, display a .txt file and delete it right away using PHP.

The image thing is cooler though, no links etc.

I though you ment like we are sending a link. Not the other thing thingy.


spyware's Avatar
Banned
0 0

The only difference is that the self-destruct site first receives an e-mail, then sends it to the "real" recipient. The destruction method was exactly the same, though.


ghost's Avatar
0 0

Well, sorry. Dint realize it at that moment. But no hard feelins? :) xD


TheSilentDrifter's Avatar
Member
0 0

If you're so worried about them reading it twice, then why don't you just call them? If it's so important, then just don't send it over e-mail. There are hundreds of different ways you can communicate with someone, and e-mail is usually my last resort. If you have to have it disappear, then it's not worth sending to them in the first place. Don't trust random people with important information, and don't EVER trust a third party e-mail system like that. If you can't design it yourself, then i don't think you should be messing with it.


ghost's Avatar
0 0

THanx for every thing… but as been computer programers i think that it is a good idea to actualy doing a modification and have the e-mail delete after reading it…. the first time i saw this was at work when one of my friends got an e-mail asking that thr email would be deleted and the sender would know when he read it…. also i know when some one applies for gov. financial aid pin # it gives you a link and then it expires so you have to write down the pin befor it expires…

i still did sent the e-mail to that person which he is a news paper reporter but first i let him know that i would be sending an e mail that would give him 60 sec. to read. and that it might end up in his spam folder… in the cmoputer science world, most things are possiable….

let us fiugre out how something like this would be possibale and let only exclusive member see how the master of programming works.. or whatever…

guys… let this be our challenge because it would be nice to know how to do this!!!

any help would be nice..

Welcome to HellBound Hackers. The hands-on approach to computer security. Learn how hackers break in, and how to keep them out. Please register to benefit from extra features and our simulated security challenges.


spyware's Avatar
Banned
0 0

You,

you scare me. Stop scaring me damn it.


ghost's Avatar
0 0

off topic @ regedit

Have you ever abused a synthetic drug? it is th egarmer


ghost's Avatar
0 0

Mr_Cheese wrote: if you want the email to be deleted when opened. have all the text in an image. host the image somewhere, then have an .htaccess in the folder so once the image is reviewed, its over written.

that would work. however some security settings you have to click "allow images" when reading hte email, so the text wont appear straight away. Hmmm nice idea cheese, I like that. However, I think the image will still be accessible since its stored on hd unless the new image overwrites the old one which I doubt.


reaper4334's Avatar
Member
0 0

Cheese and Spyware's ideas were good. The only problem I can see is, as mentioned above they may be cached in a temporary files folder or something, right? Can't see a simple way around that myself.