funsec mailing list archives

RE: Strange address in mail header


From: "Gary Funck" <gary () intrepid com>
Date: Fri, 13 Jan 2006 07:38:14 -0800



Dr. Neal Krawetz wrote:
Short answer: Everything below the spoofed header is spoofed.

Actually, although that might be true for the example message,
the slightly longer answer is that you can trust the first
few Receieved lines as long as they all treverse a sequence
of trusted networks.  For example, if the Received chain is:
1. Your network
2. AOL
3. Earthlink
4. An IP called Promoserver
5. an IP associated with Publisher's Clearing House
You know that you can trust your network, therefore you can trust
its record of the incoming mail relay, which in this example is AOL.
Once you verify that the incoming relay is a valid AOL mailer, you
can then trust their record of the incoming relay, which is in this
case Earthlink. We can trust their record of the incoming relay
which in this case is an ISP called Promoserver.  We don't know
Promoserver, and we rather suspect by its name we don't want to
know Proomoserver.  In any event, we can't trust its record
indicating that this message might be from Publisher's Clearing
House.  Therefore, we likely shouldn't take off from work today
(at least not for this reason) and wait for Ben Stein to show
up at our doorstep with a check for $1,000,000.

_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: