We have a client that thinks their server is being hijacked because of some
messages they have received.  Their server is not an open relay as far as we
can tell.  I had them send me the headers from a couple of the spam
messages.  Here is one:

From: janellef [EMAIL PROTECTED]
To: [EMAIL PROTECTED]
Date: Wed, 14 Aug 2002 11:53:50 -400 (EDT)
Subject: Happy good Assumption
Message-ID: [EMAIL PROTECTED]
Received: from mx5.nyc.untd.com (mx5.nyc.untd.com [10.140.24.65])
 by m2.boston.juno.com with SMTP id AAA8XW9KSAHDUHJA
 for <[EMAIL PROTECTED]> (sender [EMAIL PROTECTED]);
 Wed, 14 Aug 2002 11:54:24 -0400 (EST)
Received: from smtp5.ifriendly.com (psmtp5.array3.laerlink.net
[63.65.123.55])
 by mx5.nyc.untd.com with SMTP id AAA8XW9KRA26K94S
 for <[EMAIL PROTECTED]> (sender [EMAIL PROTECTED]);
 Wed, 14 Aug 2002 11:54:23 -0400 (EST)
Received: from Gtprz (0-1pool31-194.nas12.portland1.or.us.da.qwest.net
[67.2.31.194])
 by smtp5.ifriendly.com (8.9.3/8.9.3) with SMTP id LAA29780
 for <[EMAIL PROTECTED]>;
 Wed, 14 Aug 2002 11:53:50 -0400 (EST)

This message was received by Garrett in the [EMAIL PROTECTED] mailbox, with a
return address of [EMAIL PROTECTED], and with an xxx-rated message.

However, my interpretation of this header is a different story: it was a
message from a qwest.net modem pool, sent by an ifriendly.com mail account
through the ifriendly.com mail server.  It then went through a untd.com
server before reaching a juno.com server and then going to the gtrott
mailbox at juno.  My suspicion is that this message was sent from someone
named [EMAIL PROTECTED] with a forged header that says it was from janellef.

Can one of our superior experts give me a reading on this?

Ben Bednarz
BC Web


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to