Security Basics mailing list archives

Re: ip address


From: Zurt <1algorta () rigel deusto es>
Date: Wed, 17 Nov 2004 00:10:27 +0100

PL wrote:

Hi,

is it possible to figure out the IP address of the sender
just by analysing the header of an email which was sent
with a free provider like Yah** ...

Thanks

Paul

The last "Received" field you see on the next message header is the source ip address:

Received: from [212.170.83.243] by ws7-3.us4.outblaze.com with http for f00barf00 () lycos com; Tue, 16 Nov 2004 18:01:45 -0500

-------- Original Message --------
From:   - Wed Nov 17 00:04:06 2004
X-UIDL:         UID6863-1080985093
X-Mozilla-Status:       0001
X-Mozilla-Status2:      00000000
Return-Path:    <f00barf00 () lycos com>
Delivered-To:   1algorta () rigel deusto es
Received: from localhost (unknown [127.0.0.1]) by mail1.deusto.es (Postfix) with ESMTP id 4589F24B01A for <1algorta () rigel deusto es>; Wed, 17 Nov 2004 00:02:01 +0100 (CET) Received: from mail1.deusto.es ([127.0.0.1]) by localhost (mail1.deusto.es [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 24337-18 for <1algorta () rigel deusto es>; Wed, 17 Nov 2004 00:01:53 +0100 (CET) Received: from webmail-outgoing.us4.outblaze.com (webmail-outgoing.us4.outblaze.com [205.158.62.67]) by mail1.deusto.es (Postfix) with ESMTP id 2D73A24B00D for <1algorta () rigel deusto es>; Wed, 17 Nov 2004 00:01:53 +0100 (CET) Received: from wfilter.us4.outblaze.com (wfilter.us4.outblaze.com [205.158.62.180]) by webmail-outgoing.us4.outblaze.com (Postfix) with QMQP id EADDE18002A4 for <1algorta () rigel deusto es>; Tue, 16 Nov 2004 23:01:46 +0000 (GMT) X-OB-Received: from unknown (208.36.123.32) by wfilter.us4.outblaze.com; 16 Nov 2004 23:01:45 -0000 Received: by ws7-3.us4.outblaze.com (Postfix, from userid 1001) id 866823384B; Tue, 16 Nov 2004 23:01:45 +0000 (GMT)
Content-Type:   text/plain; charset="iso-8859-1"
Content-Disposition:    inline
Content-Transfer-Encoding:      quoted-printable
MIME-Version:   1.0
Received: from [212.170.83.243] by ws7-3.us4.outblaze.com with http for f00barf00 () lycos com; Tue, 16 Nov 2004 18:01:45 -0500
From:   foo bar <f00barf00 () lycos com>
To:     1algorta () rigel deusto es
Date:   Tue, 16 Nov 2004 18:01:45 -0500
Subject:        ip tracing
X-Originating-Ip:       212.170.83.243
X-Originating-Server:   ws7-3.us4.outblaze.com
Message-Id:     <20041116230145.866823384B () ws7-3 us4 outblaze com>
X-Virus-Scanned:        by amavis at mail.deusto.es



foo message
--
_______________________________________________
Find what you are looking for with the Lycos Yellow Pages
http://r.lycos.com/r/yp_emailfooter/http://yellowpages.lycos.com/default.asp?SRC=lycos10

-------- End Original Message --------



--
_____
Zurt


Current thread: