Great Circle Associates Firewalls
(August 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Mail bombing made legal...
From: jim @ coltano . stortek . com
Date: Tue, 5 Aug 1997 07:38:07 -0600 (MDT)
To: firewalls @ GreatCircle . COM
Cc: firewalls @ GreatCircle . COM

Billy Verreynne wrote:

 A bit off topic, but anyway. :-)
 
 This is totally bullshit IMHO. You can trace the any e-mail back to the
 original SMTP server using the headers. Fake headers are usually easy to
 spot. When in doubt I use telnet to get into the SMPTP servers one at a
 time, up the sendmail stream, and then e-mail myself to see how a real
 header from that server looks like.
 
Yes, you can 'try' to trace these clowns with the headers, but more often
than not it gets you nowhere.  I have seen too many where the originating
host is on a subnet that is firewalled, the host does not run an smtp daemon,
or the host 'conveniently' claims all responses are to user unknown.  And with
so many picking arbitrary hosts as mailer relays, and then disappearing, 
where do you go?  I have also seen too many using fictitious domain names,
as well as using the private address spaces to further compound the problems.


Indexed By Date Previous: RE: Mail bombing made legal...
From: Chris Brenton <cbrenton @ pccmis . com>
Next: Best Practice? - internet + multiple RAS
From: Bret Watson <Bret . Watson @ bwa . net>
Indexed By Thread Previous: RE: Mail bombing made legal...
From: Chris Brenton <cbrenton @ pccmis . com>
Next: Re: Mail bombing made legal...
From: "Billy Verreynne" <vslabs @ onwe . co . za>

Google
 
Search Internet Search www.greatcircle.com