>We have a client that thinks their server is being hijacked because of some
>messages they have received...
>
>From: janellef [EMAIL PROTECTED]
Note that these may or may not be the real headers -- they are definitely
out of order, so it's very possible that they have been altered in other
ways. Any program that re-orders the headers is doing so for human
readability, so it could be doing other things to make the headers look pretty.
>Received: from mx5.nyc.untd.com (mx5.nyc.untd.com [10.140.24.65])
> by m2.boston.juno.com with SMTP id AAA8XW9KSAHDUHJA
> for <[EMAIL PROTECTED]> (sender [EMAIL PROTECTED]);
> Wed, 14 Aug 2002 11:54:24 -0400 (EST)
>Received: from smtp5.ifriendly.com (psmtp5.array3.laerlink.net [63.65.123.55])
> by mx5.nyc.untd.com with SMTP id AAA8XW9KRA26K94S
> for <[EMAIL PROTECTED]> (sender [EMAIL PROTECTED]);
> Wed, 14 Aug 2002 11:54:23 -0400 (EST)
*If* the Received: headers are in the correct order and not modified, the
E-mail came from 10.140.24.65 (a private IP), which received the E-mail
from 63.65.123.55 (the source of the spam).
However, the headers are very fishy -- I would recommend asking your client
to get the real headers, and that if they are not, they can ignore the
complaint. If they are not an open relay, and don't have any users who
would be sending spam, it's probably a false alarm.
>This message was received by Garrett in the [EMAIL PROTECTED] mailbox, with a
>return address of [EMAIL PROTECTED], and with an xxx-rated message.
>
>However, my interpretation of this header is a different story: it was a
>message from a qwest.net modem pool, sent by an ifriendly.com mail account
>through the ifriendly.com mail server.
That is the way that it looks, but it's impossible to say for certain if
the user had an account at ifriendly.com (although the "sender
[EMAIL PROTECTED]" would imply that they do).
>It then went through a untd.com
>server before reaching a juno.com server and then going to the gtrott
>mailbox at juno.
That's how I read it, too.
>My suspicion is that this message was sent from someone
>named [EMAIL PROTECTED] with a forged header that says it was from janellef.
I would guess that, too. The From: header is just whatever the spammer
puts there, they don't even have to bother forging, so it can't be trusted.
I'm not sure where your client fits in, but it looks like ifriendly.com is
the source of the E-mail.
-Scott
---
Declude: Anti-virus, Anti-spam and Anti-hijacking solutions for
IMail. http://www.declude.com
---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/