Hi Scott,

What makes the headers out of order?  They look to be from last (on top) to
first (on bottom).

I am confused by your statement:
> *If* the Received: headers are in the correct order and not modified, the
> E-mail came from 10.140.24.65 (a private IP), which received the E-mail
> from 63.65.123.55 (the source of the spam).

Are you saying the apparent source was 63.65.123.55 and the relay was
10.140.24.65?  Then what is the connection between smtp5.ifriendly.com and
psmtp5.array3.laserlink.net?  I took it to mean that one of these is an
alias for the other.

So, has anyone ever heard of ifriendly.com?

Ben


----- Original Message -----
From: "R. Scott Perry" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Tuesday, August 20, 2002 4:22 PM
Subject: Re: [IMail Forum] slightly OT: reading a possible spam header


>
> >We have a client that thinks their server is being hijacked because of
some
> >messages they have received...
> >
> >From: janellef [EMAIL PROTECTED]
>
> Note that these may or may not be the real headers -- they are definitely
> out of order, so it's very possible that they have been altered in other
> ways.  Any program that re-orders the headers is doing so for human
> readability, so it could be doing other things to make the headers look
pretty.
>
> >Received: from mx5.nyc.untd.com (mx5.nyc.untd.com [10.140.24.65])
> >  by m2.boston.juno.com with SMTP id AAA8XW9KSAHDUHJA
> >  for <[EMAIL PROTECTED]> (sender [EMAIL PROTECTED]);
> >  Wed, 14 Aug 2002 11:54:24 -0400 (EST)
> >Received: from smtp5.ifriendly.com (psmtp5.array3.laerlink.net
[63.65.123.55])
> >  by mx5.nyc.untd.com with SMTP id AAA8XW9KRA26K94S
> >  for <[EMAIL PROTECTED]> (sender [EMAIL PROTECTED]);
> >  Wed, 14 Aug 2002 11:54:23 -0400 (EST)
>
> *If* the Received: headers are in the correct order and not modified, the
> E-mail came from 10.140.24.65 (a private IP), which received the E-mail
> from 63.65.123.55 (the source of the spam).
>
> However, the headers are very fishy -- I would recommend asking your
client
> to get the real headers, and that if they are not, they can ignore the
> complaint.  If they are not an open relay, and don't have any users who
> would be sending spam, it's probably a false alarm.
>
> >This message was received by Garrett in the [EMAIL PROTECTED] mailbox, with
a
> >return address of [EMAIL PROTECTED], and with an xxx-rated message.
> >
> >However, my interpretation of this header is a different story: it was a
> >message from a qwest.net modem pool, sent by an ifriendly.com mail
account
> >through the ifriendly.com mail server.
>
> That is the way that it looks, but it's impossible to say for certain if
> the user had an account at ifriendly.com (although the "sender
> [EMAIL PROTECTED]" would imply that they do).
>
> >It then went through a untd.com
> >server before reaching a juno.com server and then going to the gtrott
> >mailbox at juno.
>
> That's how I read it, too.
>
> >My suspicion is that this message was sent from someone
> >named [EMAIL PROTECTED] with a forged header that says it was from
janellef.
>
> I would guess that, too.  The From: header is just whatever the spammer
> puts there, they don't even have to bother forging, so it can't be
trusted.
>
> I'm not sure where your client fits in, but it looks like ifriendly.com is
> the source of the E-mail.
>
>                                                     -Scott
> ---
> Declude: Anti-virus, Anti-spam and Anti-hijacking solutions for
> IMail.  http://www.declude.com
>
> ---
> [This E-mail was scanned for viruses by Declude Virus
(http://www.declude.com)]
>
>
> To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
> List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
> Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
>


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to