50 subscription requests have been received in the last 1h from
[EMAIL PROTECTED] A copy of the mail headers from the most recent of
these requests is enclosed below. The subscription requests in question are
now being cancelled.
Due to the protocols used on the Internet for mail delivery, it is extremely
easy for a malicious user to forge an electronic mail message from another
user. This vulnerability has led to a practice known as "spoofing" in list
owner jargon, through which an innocent user is subscribed to thousands of
mailing lists with the intent of filling up his mailbox and rendering his
Internet account essentially useless. This is usually done in retribution
for having posted something on a public forum which made the perpetrator
lose face.
There is unfortunately no defense against this attack. LISTSERV
automatically monitors spoofing attempts and blocks subscription requests
after a certain threshold. In addition, it will automatically undo the
subscriptions which were accepted before the spoofing attempt was detected.
Unfortunately, most other mailing list managers offer no such protection,
and the victim must cancel the subscriptions individually.
An examination of the mail headers from the original request may reveal some
information about the perpetrator. However, in most cases this person will
be a technically skilled individual who will know what steps need to be
taken in order to hide one's track. It is usually much easier to identify
the perpetrator using traditional investigative methods, such as looking for
technically skilled individuals that the victim has recently angered. It is
exceedingly rare, however, to find evidence that will stand in court.
-------------------------- Incoming mail header ----------------------------
Received: from smtp-1.findlaw.com (smtp-1-app.prod.findlaw.com [10.10.16.9])
by listserv.prod.findlaw.com (Pro-8.9.3/Pro-8.9.3) with ESMTP id IAA31306
for <[EMAIL PROTECTED]>; Mon, 10 Jul 2000 08:59:19 -0700
From: [EMAIL PROTECTED]
Received: from lists.prod.findlaw.com (lists-app.prod.findlaw.com [10.10.16.13])
by smtp-1.findlaw.com (8.9.3/8.8.7) with ESMTP id IAA03065
for <[EMAIL PROTECTED]>; Mon, 10 Jul 2000 08:59:19 -0700
Received: (from nobody@localhost)
by lists.prod.findlaw.com (8.9.3/8.9.3) id IAA01433
for [EMAIL PROTECTED]; Mon, 10 Jul 2000 08:59:20 -0700
Date: Mon, 10 Jul 2000 08:59:20 -0700
Message-Id: <[EMAIL PROTECTED]>
X-Authentication-Warning: lists.prod.findlaw.com: nobody set sender to
[EMAIL PROTECTED] using -f
To: [EMAIL PROTECTED]
Subject:
Spoofing alert ([email protected])
L-Soft list server at Legalminds (1.8d) Mon, 10 Jul 2000 09:31:32 -0700
