Security Basics mailing list archives

Re: Distressing, possibly life threatening emails from free accounts


From: Aj Effin Reznor <aj () reznor com>
Date: Wed, 4 Jun 2003 13:17:07 -0700 (PDT)

"Juan Velasquez was known to say....."

heh.
    thats funny.
The IP that will appear at the top of the email headers will be a Yahoo 
Web server.
Since it was after all,  a Yahoo Web Server which sent the email on the 
behalf of a yahoo web serfer.


I see you're using Mozilla for your mail.  I'm guessing you don't do much
time reading headers.  At least not from hotmail and yahoo addys.

See, there's a nifty, little thing in the header, labeled X-Originating-IP.
Care to venture a guess?  That's the webserver (yahoo's, hotmail's, etc)
stamping the IP of the client that logged in and sent the mail.  Not all
webmail services do this, however most do.

Sure, the Received headers are going to show the path the mail took and
will indeed include the IP of yahoo's servers.  There's more to headers
than just the Received fields, and in this case they do indeed include
the IP that the mail came from.

So, to summarize: yer off, and, erm, Mr. MeLtDoWn was on the money, sorry.

-aj.





---------------------------------------------------------------------------
----------------------------------------------------------------------------


Current thread: