Re: Virus origin

From: srm (user_at_nospam.org)
Date: 11/22/04


Date: Mon, 22 Nov 2004 22:56:00 +0100

Peter Pearson wrote:

> srm wrote:

>> According to the 'Received:' trace, the message originated at:
>> host217-42-163-55.range217-42.btcentralplus.com  ([217.42.163.55]
>> helo=frenchentree.com)
>
> The sender can insert false "Received:" lines, but these will
> all appear *after* the valid "Received:" lines inserted by
> the legitimate mail transporters that subsequently handle the
> message. Work your way down the "Received:" lines until you
> come to a "by" that you don't trust. Ignore that and all
> subsequent "Received:" lines: they may be fake.

The 'Received' header I quoted was the oldest (ie, the first) in the chain.
Many of the virus mails we're receiving have the first Received header
suggesting they've been mailed via a dial-up node near him on a system
(Wanadoo) I know he uses. But I spoke to him today and here swears he's up
to date with all AV scanners, firewall etc. It's just that I also know he's
not brilliantly technical.

It doesn't worry me too much - we're on Linux here and the Amavis/AntiVir
system seems to be intercepting everything. It's just annoying having had
to make space for around 250 virus emails in the past 5 days, not to
mention the waste of bandwidth...

-- 
@+


Relevant Pages

  • Re: Setup problem with SenderID and OWA
    ... >mail with OWA. ... of the Exchange server, not the IP address of the machine running the ... >Sample SMTP Header from Exchange server.... ... surely isn't the one inserted by the receiving server. ...
    (microsoft.public.exchange.admin)
  • Re: Email Virus
    ... >>>Each Received is a postmaster receiving the message with ... > header as out017.verizon.net but didn't include an IP address. ... > enter.net ISP is the true sender. ...
    (comp.os.linux.security)
  • Re: Lynn at garlic.com
    ... please not that the only part of the e-mail I am receiving is from my ISP telling me that a virus has been deleted. ... it is probably somebody impersonating "lynn@xxxxxxxxxx" (that ... header information (many don't bother since ...
    (bit.listserv.ibm-main)
  • Re: Spoofing "TO" Address in email
    ... >>As a test, I sent myself an email without addressing the TO field at all, ... >>Doesn't the recipient's email address have to be in the header SOMEWHERE ... >>in order for the recipient to actually receive it? ... >>receiving an email as a BCC recipient if sent from Road Runner email ...
    (alt.computer.security)
  • Re: Spoofing "TO" Address in email
    ... value may not show up in any header. ... >receiving an email as a BCC recipient if sent from Road Runner email ... between the sending mail server ... "RCPT TO:" which is what actually controls delivery only gets passed ...
    (alt.computer.security)