Great Circle Associates Firewalls
(February 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Disturbing e-mail
From: Gordy Thompson <gordy @ nytimes . com>
Date: Sun, 16 Feb 1997 20:45:51 -0500
To: firewalls @ greatcircle . com

At 12:07 AM 2/17/97 +0000, harley @
 icrf .
 icnet .
 uk wrote:

>[snipped]
>> thus capturing the user's email address. It would be trivial to forge mail
>> back to the user with the user's own address in the From: field. I suspect
>> that this is what NaughtyRobot is doing (geocities is host to many web
>> sites), but I can't say for certain in light of their silence on my 
>> complaint.
>
>Geocities hosts some distinctly darkside websites. Or, if you prefer, 
>seems to have a fairly liberal policy on content. However, I don't 
>think you can assume that geocities is the original source.

        You're absolutely right, and I was careless in the way I expressed
myself: I should have included the possibility that the mystery mail
earlier from the user/victim to a geocities address was a coincidence, and
that the forged "NaughtyRobot" mail was injected into the geocities SMTP
port and thereafter bore sendmail headers that appeared to show it
originated there. My apologies to geocities for any unintended slur.

>The reason I
>tend to de-lurk when these questions come up is the hope that 
>(since my sources on these topics are usually pretty good) I can 
>help forestall long, off-topic threads.

        Yep. I'm shutting up now [:-].


==========================================================================
Gordon T. Thompson                                      gordy @
 nytimes .
 com
Manager, Internet Services                              212 556 1386
The New York Times                                      fax: 212 556 1636
       This letter has been modified as follows from its original
           version: It has been formatted to fit your screen.

Indexed By Date Previous: Dialup security
From: "Ralph E. Marcuccilli" <ralphm @ starfinancial . com>
Next: Re: Linux Tripwire-1.2
From: "Leon OBrien" <leon @ networx . com . au>
Indexed By Thread Previous: Re: Disturbing e-mail
From: harley @ icrf . icnet . uk
Next: loggin events
From: Ziv Dascalu <ziv @ AbirNet . com>

Google
 
Search Internet Search www.greatcircle.com