That�s for the answer.

In that case, with the discussion concerning sending the automatic virus
notices, what about the thoughts of sending it to Postmaster and/or
abuse at the IP address?

That way, you would have an almost guaranteed way of sending it to
correct server.

I know we have the mail server IP address in the mail server alias list,
as some tests, such as AOL, send messages to postmaster@"IP address".

What are other admins out there doing?

Is it a requirement to receive e-mail to postmaster@IP?

John Tolmachoff 
IT Manager, Network Engineer
211 E. Imperial Hwy., Suite 106
Fullerton, CA� 92835
714-578-7999, ext. 104
[EMAIL PROTECTED]
www.reliancesoft.com
�


-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]] On Behalf Of R. Scott Perry
Sent: Monday, April 22, 2002 7:17 AM
To: [EMAIL PROTECTED]
Subject: Re: [IMail Forum] Forged Headers


>Although I know the header can be forged, what about the from IP
address
>on the top line of the header?
>
>That line is added by the receiving mail server, which takes the IP
>directly from the connection communication, correct?
>
>Or do I not completely understand how headers are forged? Probably!  :(

It sounds like you do understand.  :)

There are two levels of trust involved.  One is trusting the header (IE 
that it was added by a trusted source), the other is trusting the 
information within the header.

The only headers that you can trust are the ones that your mailserver 
adds.  However, the information within those headers may or may not be 
trustable.

In *most* cases, you can only trust the first Received: header, and the 
only (useful) information in there that you can trust is the IP 
address.  Specifically, you can not always trust the domain name that is

listed (since it comes from the remote mailserver, which you can not
always 
trust).

The IP address in the first Received: header should be correct about 
99.9999% of the time.  It's possible to spoof an IP address, but it is 
*very* difficult with TCP/IP connection (not only does the hacker have
to 
enter an invalid IP address, they have to predict sequence numbers and 
server responses).  The hacker will not know if his mail was sent if he 
uses a spoofed IP address.  However, it can happen.

There is a lot of information you can get (or guess) from the other 
headers, but the accuracy of the information varies.

                                                    -Scott
---
Declude: Anti-virus, Anti-spam and Anti-hijacking solutions for 
IMail.  http://www.declude.com

---
[This E-mail was scanned for viruses by Declude Virus
(http://www.declude.com)]


Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/

Please visit the Knowledge Base for answers to frequently asked
questions:  http://www.ipswitch.com/support/IMail/


Please visit http://www.ipswitch.com/support/mailing-lists.html
to be removed from this list.

An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/

Please visit the Knowledge Base for answers to frequently asked
questions:  http://www.ipswitch.com/support/IMail/

Reply via email to