Re: Obvious manipulation of e-mail headers - what good are they?

From: George Hester (hesterloli_at_hotmail.com)
Date: 04/29/05


Date: Thu, 28 Apr 2005 20:31:46 -0400

I did not post all the headers because that was not necessary for my point. But if you want them here they are I don't see how the rest of them say anything about the %RANDOMIZATION% that is being used here:

Return-path: <iheskhfcbe@action.com.au>
Received: from ms-mta-03 (ms-mta-03-smtp [10.10.4.10])
 by ms-mss-01.nyroc.rr.com
 (iPlanet Messaging Server 5.2 HotFix 2.04 (built Feb 8 2005))
 with ESMTP id <0IFM003G4Y3VVL@ms-mss-01.nyroc.rr.com>; Wed,
 27 Apr 2005 22:40:46 -0400 (EDT)
Received: from orngca-mx-03.mgw.rr.com
 (orngca-mx-03.mgw.rr.com [66.75.160.130]) by ms-mta-03.nyroc.rr.com
 (iPlanet Messaging Server 5.2 HotFix 2.04 (built Feb 8 2005))
 with ESMTP id <0IFM00L0XY19O9@ms-mta-03.nyroc.rr.com>; Wed,
 27 Apr 2005 22:39:15 -0400 (EDT)
Received: from 84-121-165-206.onocable.ono.com (84.121.165.206)
 by orngca-mx-03.mgw.rr.com with SMTP; Wed, 27 Apr 2005 22:40:28 -0400
Received: from %STATIC_3WORD
 (IMLI-852-880.%S_1FROM_DOMAIN [%LIST_IP] (may be forged))
 by %STATIC_2WORD.%S_1FROM_DOMAIN (MOS 3.3.6-GR)
 with ESMTP id DLT75284 (AUTH %STATIC_3WORD-02) ; Thu,
 28 Apr 2005 01:37:32 -0200 (IST)
Date: Wed, 27 Apr 2005 22:39:15 -0400 (EDT)
Date-warning: Date header was inserted by ms-mta-03.nyroc.rr.com
From: Martha Peck <iheskhfcbe@action.com.au>
Subject: Message subject
To: dverdow@nycap.rr.com
Message-id: <3kmqqq$ehe806@orngca-mx-03.mgw.rr.com>
MIME-version: 1.0
Content-type: TEXT/PLAIN
Content-transfer-encoding: 8BIT

My point being this allows the ISP of the spammer to deny they are part of the problem. Call it a rant if you choose some rants are true you know.

-- 
George Hester
_________________________________
"N. Miller" <anonymous@discussions.microsoft.com> wrote in message news:MPG.1cdac7b495795dc398a804@msnews.microsoft.com...
> In article <Obat3G#SFHA.3556@TK2MSFTNGP10.phx.gbl>, Karl Levinson, mvp 
> says...
> 
> > I think the problem is whatever software you
> > are using to try to get the SMTP headers... either it isn't giving you the
> > entire headers, or you have to figure out how to access them.
> 
> I don't think the OP had a problem finding the complete headers. He 
> mentioned that he was posting "partial" headers. I think he went wrong in 
> expecting every "Received: from * by *" header to be truthful; or, perhaps 
> more likely, just ranting because those headers can be so easily forged.
> 
> -- 
> Norman
> ~Win dain a lotica, En vai tu ri, Si lo ta
> ~Fin dein a loluca, En dragu a sei lain
> ~Vi fa-ru les shutai am, En riga-lint


Relevant Pages

  • Re: Headers & Footers
    ... appreciate the rant. ... > headers and footers. ... > I looked through the user groups for a way to turn this ...
    (microsoft.public.word.pagelayout)
  • Re: yet another "eBay is broken" rant
    ... yet another "eBay is broken" rant ... NNTP-Posting-Host: 75.83.39.53 ... Xref: prodigy.net alt.marketing.online.ebay:649932 ...
    (alt.marketing.online.ebay)
  • Re: Is it really true that NTFS is secure?
    ... George Hester wrote: ... > open #my.ip.address# 'chnaged ip for privacy ... headers. ... My kids seem to always be around, remove them to reply directly to me. ...
    (microsoft.public.security)