Hi Scott, What makes the headers out of order? They look to be from last (on top) to first (on bottom).
I am confused by your statement: > *If* the Received: headers are in the correct order and not modified, the > E-mail came from 10.140.24.65 (a private IP), which received the E-mail > from 63.65.123.55 (the source of the spam). Are you saying the apparent source was 63.65.123.55 and the relay was 10.140.24.65? Then what is the connection between smtp5.ifriendly.com and psmtp5.array3.laserlink.net? I took it to mean that one of these is an alias for the other. So, has anyone ever heard of ifriendly.com? Ben ----- Original Message ----- From: "R. Scott Perry" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Tuesday, August 20, 2002 4:22 PM Subject: Re: [IMail Forum] slightly OT: reading a possible spam header > > >We have a client that thinks their server is being hijacked because of some > >messages they have received... > > > >From: janellef [EMAIL PROTECTED] > > Note that these may or may not be the real headers -- they are definitely > out of order, so it's very possible that they have been altered in other > ways. Any program that re-orders the headers is doing so for human > readability, so it could be doing other things to make the headers look pretty. > > >Received: from mx5.nyc.untd.com (mx5.nyc.untd.com [10.140.24.65]) > > by m2.boston.juno.com with SMTP id AAA8XW9KSAHDUHJA > > for <[EMAIL PROTECTED]> (sender [EMAIL PROTECTED]); > > Wed, 14 Aug 2002 11:54:24 -0400 (EST) > >Received: from smtp5.ifriendly.com (psmtp5.array3.laerlink.net [63.65.123.55]) > > by mx5.nyc.untd.com with SMTP id AAA8XW9KRA26K94S > > for <[EMAIL PROTECTED]> (sender [EMAIL PROTECTED]); > > Wed, 14 Aug 2002 11:54:23 -0400 (EST) > > *If* the Received: headers are in the correct order and not modified, the > E-mail came from 10.140.24.65 (a private IP), which received the E-mail > from 63.65.123.55 (the source of the spam). > > However, the headers are very fishy -- I would recommend asking your client > to get the real headers, and that if they are not, they can ignore the > complaint. If they are not an open relay, and don't have any users who > would be sending spam, it's probably a false alarm. > > >This message was received by Garrett in the [EMAIL PROTECTED] mailbox, with a > >return address of [EMAIL PROTECTED], and with an xxx-rated message. > > > >However, my interpretation of this header is a different story: it was a > >message from a qwest.net modem pool, sent by an ifriendly.com mail account > >through the ifriendly.com mail server. > > That is the way that it looks, but it's impossible to say for certain if > the user had an account at ifriendly.com (although the "sender > [EMAIL PROTECTED]" would imply that they do). > > >It then went through a untd.com > >server before reaching a juno.com server and then going to the gtrott > >mailbox at juno. > > That's how I read it, too. > > >My suspicion is that this message was sent from someone > >named [EMAIL PROTECTED] with a forged header that says it was from janellef. > > I would guess that, too. The From: header is just whatever the spammer > puts there, they don't even have to bother forging, so it can't be trusted. > > I'm not sure where your client fits in, but it looks like ifriendly.com is > the source of the E-mail. > > -Scott > --- > Declude: Anti-virus, Anti-spam and Anti-hijacking solutions for > IMail. http://www.declude.com > > --- > [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] > > > To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html > List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ > Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/ > To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
