Full Disclosure mailing list archives
Re: VeriSign's fake SMTP server for SiteFinder
From: Joshua Levitsky <jlevitsk () joshie com>
Date: Mon, 22 Sep 2003 19:17:43 -0400
On Sep 22, 2003, at 6:02 PM, Joshua Thomas wrote:
> But why they wait until the DATA command is a total mystery to me. It
> seems much more logical to bounce the message after the RCPT TO:
> command.
<conspiracy theory>
To read our mail?
</conspiracy theory>
They will read our mail when they accept the DATA command and all after it. This will happen. You will see.
Right now they take in the address of who you are sending to and who is sending. What a wonderful way to collect valid email addresses. First the MAIL FROM will be a correct address most of the time. The RCPT TO will be wrong 100% of the time, but they could employ scripts with some logic to see things like user () netscpe com is really user () netscape com and such. Many typos are repeated in the same way by many people.
Can't wait for the spam to start flowing from that list of users they are collecting. Of course Verisign will protect their customers from the spam. That'll be part of the deal with the spammers they sell to.
Current thread:
- Re: VeriSign's fake SMTP server for SiteFinder, (continued)
- Re: VeriSign's fake SMTP server for SiteFinder Brent J. Nordquist (Sep 22)
- Re: VeriSign's fake SMTP server for SiteFinder Michal Zalewski (Sep 22)
- Re: VeriSign's fake SMTP server for SiteFinder Damian Gerow (Sep 22)
- Re: VeriSign's fake SMTP server for SiteFinder fulldisclosure (Sep 22)
- Re: VeriSign's fake SMTP server for SiteFinder Dan Rowles (Sep 22)
- Re: VeriSign's fake SMTP server for SiteFinder Jonathan A. Zdziarski (Sep 22)
- Re: VeriSign's fake SMTP server for SiteFinder Joshua Levitsky (Sep 22)
- Re: VeriSign's fake SMTP server for SiteFinder Valdis . Kletnieks (Sep 22)
- Re: VeriSign's fake SMTP server for SiteFinder Jonathan A. Zdziarski (Sep 22)
- Re: VeriSign's fake SMTP server for SiteFinder Nate Hill (Sep 22)
- RE: VeriSign's fake SMTP server for SiteFinder Joshua Thomas (Sep 22)
- Re: VeriSign's fake SMTP server for SiteFinder Joshua Levitsky (Sep 22)
- Re: VeriSign's fake SMTP server for SiteFinder Geoincidents (Sep 22)
- Re: VeriSign's fake SMTP server for SiteFinder Ng Pheng Siong (Sep 22)
- Re: VeriSign's fake SMTP server for SiteFinder Joshua Levitsky (Sep 22)
- Re: VeriSign's fake SMTP server for SiteFinder Damian Gerow (Sep 22)
- Re: VeriSign's fake SMTP server for SiteFinder Joshua Levitsky (Sep 22)