Great Circle Associates Firewalls
(May 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Tracking down the sender of an email...
From: Alan <alano @ teleport . com>
Date: Fri, 16 May 1997 11:43:04 -0700 (PDT)
To: chmielewskil @ subway . com
Cc: firewalls @ GreatCircle . COM
In-reply-to: <199705161729 . KAA09338 @ m9 . sprynet . com>

On Fri, 16 May 1997, Louis T. Chmielewski wrote:

> Hello all,
> 	I'm relatively new to the security game, but I'm learning.  We recently
> had someone 'mail bomb' us with about 500 messages.  I'd like to track it
> down, but it looks like the sender used an Anonymous mailer.  Can someone
> tell me how to look at the header of the messages and determine where it
> came from, and who really sent it?

If it came from an anonymous remailer, chances are pretty slim.
(Remailers can be chained.  Unless you can get warrents for the system
logs on all the remailers in that chain, you are pretty much SOL.)

> Also, how can I avoid this 'situation' in the future?

You can filter out mail from anonymous remailers.  Or you can use procmail
to eliminate duplicate messages.  (Forcing them to send 500 unique
messges.  Not hard, but more work.)

Putting limits on incoming mail is not hard.  Preventing damage from a
determined individual is alot harder.



References:
Indexed By Date Previous: RE: Firewall
From: Eric Tebelak <elt @ usweb . com>
Next: Re: Tracking down the sender of an email...
From: long-morrow @ CS . YALE . EDU
Indexed By Thread Previous: Tracking down the sender of an email...
From: "Louis T. Chmielewski" <chmielewskil @ sprynet . com>
Next: Re: Tracking down the sender of an email...
From: Root Admin-KSoft <root @ sibernet . com . tr>

Google
 
Search Internet Search www.greatcircle.com