Re: IP number question

From: Michael J. Pelletier (mjpelletier_at_mjpelletier.com)
Date: 01/27/05


Date: Thu, 27 Jan 2005 12:22:51 -0800

Walter Roberson wrote:

> In article <6d0Kd.10797$rw.4141@fed1read04>,
> Michael J. Pelletier <mjpelletier@mjpelletier.com> wrote:
> |Walter Roberson wrote:
>
> |> but I can assure you with 100% certainty that my message
> |> was NOT posted to the groups.google.com news server, and that
> |> that IP address has no special article exchange arrangement
> |> with google. I'm quite certain of that -- I administer the system
> |> in question myself, and I administer the company firewall myself.
> |> There is NO direct way from 192.70.172.31 to google's posting
> |> service.
>
> |Not sure what you are saying. Your IP (via the last post) is
> |192.70.172.31. The IP block is owned by the Canadian Gov and your IP goes
> |to a Institute of Biodiagnostics of Canada. I assume that is where you
> |posted the last message.
>
> |Now your statement is that there is no way your IP address can be used to
> |post news articles?
>
> What I am pointing out is that my system has no direct connection to
> google's posting service, and so it is not possible for google
> to have -directly- received the posting from my system. Therefore google
> cannot have "firsthand" knowledge of the IP address that I was posting
> from: it has to rely on something else to tell it the IP address
> that was used. And that something else relies on something else yet,
> and so on down the chain. If I can find any system anywhere in the
> world that is willing to trust me when I send IHAVE verbs, then
> I can present a posting whose headers *claim* whatever IP address
> I care to insert. The next hop will copy the forged header, the
> hop after that will too, and so on until it gets to google or your
> news server and you retrieve the message and thus display the
> header that I injected rather than where the posting really came from.

Yup, but there is an awful lot of sequence numbers to guess in a
proportionally small amount of time....

Interesting. I thought that news servers operated like mail servers. True
you can forge the envelope from, etc but the mail server will record the IP
address that connected to it and record it into the header.

I guess what you are saying is that news servers are not as "smart". True?
If so, thanks for the explanation. I guess you learn something everyday!

Michael



Relevant Pages

  • Re: Boy, this newsgroup has certainly been taken over! [Xnews]
    ... I have a similar rule in my Score file, ... news servers don't allow me to filter on that header at the ... I can't score on that header either with my news service. ... The following filter should work for this guy: ...
    (news.software.readers)
  • Re: Boy, this newsgroup has certainly been taken over! [Xnews]
    ... I very much like that Xnews feature :-) ... news servers don't allow me to filter on that header at the ... I can't score on that header either with my news service. ... The following filter should work for this guy: ...
    (news.software.readers)
  • Re: [xnews] new icons and formatting?
    ... >>> News servers and agents aren't required to support anything more than ... > limit on the length of header lines, body lines, /or header logical ... Each header field is logically a single line of characters comprising ...
    (news.software.readers)