funsec mailing list archives
RE: Strange address in mail header
From: "Gary Funck" <gary () intrepid com>
Date: Fri, 13 Jan 2006 07:38:14 -0800
Dr. Neal Krawetz wrote:
Short answer: Everything below the spoofed header is spoofed.
Actually, although that might be true for the example message, the slightly longer answer is that you can trust the first few Receieved lines as long as they all treverse a sequence of trusted networks. For example, if the Received chain is: 1. Your network 2. AOL 3. Earthlink 4. An IP called Promoserver 5. an IP associated with Publisher's Clearing House You know that you can trust your network, therefore you can trust its record of the incoming mail relay, which in this example is AOL. Once you verify that the incoming relay is a valid AOL mailer, you can then trust their record of the incoming relay, which is in this case Earthlink. We can trust their record of the incoming relay which in this case is an ISP called Promoserver. We don't know Promoserver, and we rather suspect by its name we don't want to know Proomoserver. In any event, we can't trust its record indicating that this message might be from Publisher's Clearing House. Therefore, we likely shouldn't take off from work today (at least not for this reason) and wait for Ben Stein to show up at our doorstep with a check for $1,000,000. _______________________________________________ Fun and Misc security discussion for OT posts. https://linuxbox.org/cgi-bin/mailman/listinfo/funsec Note: funsec is a public and open mailing list.
Current thread:
- Strange address in mail header Larry Seltzer (Jan 13)
- Re: Strange address in mail header Dr. Neal Krawetz (Jan 13)
- RE: Strange address in mail header Gary Funck (Jan 13)
- Re: Strange address in mail header Valdis . Kletnieks (Jan 13)
- RE: Strange address in mail header Gary Funck (Jan 13)
- Re: Strange address in mail header Dr. Neal Krawetz (Jan 13)
