Re: [Full-Disclosure] SPAM and "undisclosed recipients"

Valdis.Kletnieks_at_vt.edu
Date: 11/15/03

  • Next message: Pentest Security Advisories: "[Full-Disclosure] Re: Serious flaws in bluetooth security lead to disclosure of personal data"
    To: Kristian Hermansen <khermansen@ht-technology.com>
    Date: Sat, 15 Nov 2003 12:07:53 -0500
    
    
    

    On Sat, 15 Nov 2003 11:10:37 EST, Kristian Hermansen <khermansen@ht-technology.com> said:

    > I have a small question about SPAM emails that are sent to "undisclosed
    > recipients". Does this just mean that the server stripped the header before
    > sending it to my account? I don't understand how it could make it to my
    > server, let alone my email account, if nothing was specified. Does this
    > raise any security issues?

    Mail is actually routed via the RFC821/2821 MAIL FROM and RCPT TO commands, not
    by the RFC822/2822 From:/To:/cc:/Bcc: lines. Think - mail from this list gets to you
    even though you're not in the To: line. :)

    "undisclosed recipients" just means that somebody/something decided to add into
    the rfc822 headers the fact that the mail was bcc'ed to multiple people.

    See rfc2822, sections 3.6.3 and 5 about bcc: for more details on this.

    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html



  • Next message: Pentest Security Advisories: "[Full-Disclosure] Re: Serious flaws in bluetooth security lead to disclosure of personal data"

    Relevant Pages

    • Re: How to kill spam?
      ... The e-mail client sends a RCPT TO command to the mail server saying who gets the message. ... Multiple RCPT TO commands are sent following by a single DATA command when sending a message to multiple recipients. ... be aware that some good senders may put you in the Bcc field which you cannot test because it was never included in the header portion of their message. ... You will need to define a whitelist rule to account for any senders whose mails you want to keep that do not put you in the To or Cc header. ...
      (microsoft.public.windowsxp.newusers)
    • Re: How to send large email
      ... Your ISP may include personal web pages so you could use the disk ... > which include a personal web page account where you could upload the file. ... > When putting recipients into the Bcc header, ...
      (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
    • Re: reply address
      ... What you want recipients to see in the From header is dictated by what ... you enter in the E-mail field in the account you defined in Outlook. ... The Reply-To header is NOT the From header. ... The recipient will see in their e-mail client whatever is in the From ...
      (microsoft.public.outlook.general)
    • Re: Objection rec.knives PLEASE IGNORE if you dont want to see an off topic post
      ... I ignore bragging, and I expect that if you post on a newsgroup about knives you post about knives, at least initially. ... It's at the point that if Robert posts a legitimate request, ... I definitely don't think you'd lose your account at all. ... Nah it's okay I don't feel the sarcasm at all, the header information wasn't meant for you. ...
      (rec.knives)
    • Re: Code example for foreign connector (c#) for Exchange 2007
      ... header fields as the recipients of the message. ... Is that so you can lookup users on the Exchange system as though they ... from coming back to the foreign users when I post it thru the gateway. ...
      (microsoft.public.exchange.development)

  • Quantcast