Backtracking EMAIL Messages

Category: Tutorial


<< Buy This Book on Amazon >>

392 views since 2007-05-18, updated at 2008-08-29. Bookmark this: Backtracking EMAIL Messages

Description


Backtracking EMAIL Messages  

Tracking email back to its source: Twisted Evil
cause i hate spammers... Evil or Very Mad

Ask most people how they determine who sent them an email message and the response is almost universally, "By the From line." Unfortunately this symptomatic of the current confusion among internet users as to where particular messages come from and who is spreading spam and viruses. The "From" header is little more than a courtesy to the person receiving the message. People spreading spam and viruses are rarely courteous. In short, if there is any question about where a particular email message came from the safe bet is to assume the "From" header is forged.

So how do you determine where a message actually came from? You have to understand how email messages are put together in order to backtrack an email message. SMTP is a text based protocol for transferring messages across the internet. A series of headers are placed in front of the data portion of the message. By examining the headers you can usually backtrack a message to the source network, sometimes the source host. A more detailed essay on reading email headers can be found .

If you are using Outlook or Outlook Express you can view the headers by right clicking on the message and selecting properties or options.

Below are listed the headers of an actual spam message I received. I've changed my email address and the name of my server for obvious reasons. I've also double spaced the headers to make them more readable.


Return-Path: <s359dyxtt@yahoo.com>

X-Original-To: davar@example.com

Delivered-To: davar@example.com

Received: from 12-218-172-108.client.mchsi.com (12-218-172-108.client.mchsi.com [12.218.172.108])
by mailhost.example.com (Postfix) with SMTP id 1F9B8511C7
for <davar@example.com>; Sun, 16 Nov 2003 09:50:37 -0800 (PST)

Received: from (HELO 0udjou) [193.12.169.0] by 12-218-172-108.client.mchsi.com with ESMTP id <536806-74276>; Sun, 16 Nov 2003 19:42:31  0200

Message-ID: <n5-l067n7z$46-z$-n@eo2.32574>

From: "Maricela Paulson" <s359dyxtt@yahoo.com>

Reply-To: "Maricela Paulson" <s359dyxtt@yahoo.com>

To: davar@example.com

Subject: STOP-PAYING For Your PAY-PER-VIEW, Movie Channels, Mature Channels...isha

Date: Sun, 16 Nov 2003 19:42:31  0200

X-Mailer: Internet Mail Service (5.5.2650.21)

X-Priority: 3

MIME-Version: 1.0

Content-Type: multipart/alternative; boundary="MIMEStream=_0 211404_90873633350646_4032088448"


According to the From header this message is from Maricela Paulson at s359dyxxt@yahoo.com. I could just fire off a message to abuse@yahoo.com, but that would be waste of time. This message didn't come from yahoo's email service.

The header most likely to be useful in determining the actual source of an email message is the Received header. According to the top-most Received header this message was received from the host 12-218-172-108.client.mchsi.com with the ip address of 21.218.172.108 by my server mailhost.example.com. An important item to consider is at what point in the chain does the email system become untrusted? I consider anything beyond my own email server to be an unreliable source of information. Because this header was generated by my email server it is reasonable for me to accept it at face value.

The next Received header (which is chronologically the first) shows the remote email server accepting the message from the host 0udjou with the ip 193.12.169.0. Those of you who know anything about IP will realize that that is not a valid host IP address. In addition, any hostname that ends in client.mchsi.com is unlikely to be an authorized email server. This has every sign of being a cracked client system.


Here's is where we start digging. By default Windows is somewhat lacking in network diagnostic tools; however, you can use the tools at to do your own checking.

davar@nqh9k:[/home/davar] $whois 12.218.172.108

AT

Download this book from Usenet
DOWNLOAD Free register and download UseNet downloader, then you can free download from UseNet.

Free Download "Backtracking EMAIL Messages" from Usenet!

Buy this book from amazon


Disclaimer:
Contents of this page are indexed from the Internet. All actions are under your responsability. Email us to report illegal contents or external links and we'll remove them immediately.

Search More...

Backtracking EMAIL Messages

Search free ebooks in ebookee.com!


Links

Free Trade Magazine Subscriptions & Technical Document Downloads

Search and Buy
<< Search and Buy This Book on Amazon >>

Download this book from Usenet
DOWNLOAD How to download:
Free register to download UseNet downloader and install, then search book title and start downloading. You can DOWNLOAD 150GB for free! Register and Download NOW!

Free Download "Backtracking EMAIL Messages" from Usenet!

Download Link 2


No download links here
Please check the description for download links if any or do a search to find alternative books.

Can't Download?
Please search mirrors if you can't find download links for "Backtracking EMAIL Messages" in "Description" and someone else may update the links. Check the comments when back to find any updates.

Search Mirrors
Maybe some mirror pages will be helpful, search this book at top of this page or click here to find more info.


Related Books


Books related to "Backtracking EMAIL Messages":

  1. Ebooks list page : 131
  2. ESG: Realizing and Maximizing an Email Archive ROI with EMC SourceOne Email Management, Free EMC Analyst Report
  3. ESG: Realizing and Maximizing an Email Archive ROI with EMC SourceOne Email Management, Free EMC Analyst Report
  4. ESG: Realizing and Maximizing an Email Archive ROI with EMC SourceOne Email Management, Free EMC Analyst Report
  5. ESG: Realizing and Maximizing an Email Archive ROI with EMC SourceOne Email Management, Free EMC Analyst Report
  6. ESG: Realizing and Maximizing an Email Archive ROI with EMC SourceOne Email Management, Free EMC Analyst Report
  7. [share_ebook] Linux Email: Set Up and Run a Small Office Email Server
  8. Safe Email - Seven Important Tips for Better Email Security in 2009, Free Aberdeen Group Research Report
  9. Safe Email - Seven Important Tips for Better Email Security in 2009, Free Aberdeen Group Research Report
  10. Safe Email - Seven Important Tips for Better Email Security in 2009, Free Aberdeen Group Research Report
  11. Safe Email - Seven Important Tips for Better Email Security in 2009, Free Aberdeen Group Research Report
  12. Safe Email - Seven Important Tips for Better Email Security in 2009, Free Aberdeen Group Research Report
  13. IDC Technology Spotlight: EMC SourceOne Email Management: A Next Generation Email Archiving Solution, Free EMC Analyst Report
  14. IDC Technology Spotlight: EMC SourceOne Email Management: A Next Generation Email Archiving Solution, Free EMC Analyst Report
  15. IDC Technology Spotlight: EMC SourceOne Email Management: A Next Generation Email Archiving Solution, Free EMC Analyst Report
  16. IDC Technology Spotlight: EMC SourceOne Email Management: A Next Generation Email Archiving Solution, Free EMC Analyst Report

Comments


No comments for "Backtracking EMAIL Messages".

Usenet Binaries anonym mit DSL Speed downloaden inkl. gratis Software

    Add Your Comments

    1. Download links and password may be in the description section, read description carefully!
    2. Do a search to find mirrors if no download links or dead links.

    required

    required, hidden

    need login

    required

    More Categories

    We Recommend

    Email Subscribe

    Enter your email address:

    Delivered by FeedBurner

    Feed & Bookmark

    • Add to Google Reader or Homepage

    Sponsored Links

    Back to Top