Full Disclosure mailing list archives

Re: VeriSign's fake SMTP server for SiteFinder


From: Joshua Levitsky <jlevitsk () joshie com>
Date: Mon, 22 Sep 2003 19:17:43 -0400


On Sep 22, 2003, at 6:02 PM, Joshua Thomas wrote:

> But why they wait until the DATA command is a total mystery to me. It
> seems much more logical to bounce the message after the RCPT TO:
> command.

<conspiracy theory>

To read our mail?

</conspiracy theory>

They will read our mail when they accept the DATA command and all after it. This will happen. You will see.

Right now they take in the address of who you are sending to and who is sending. What a wonderful way to collect valid email addresses. First the MAIL FROM will be a correct address most of the time. The RCPT TO will be wrong 100% of the time, but they could employ scripts with some logic to see things like user () netscpe com is really user () netscape com and such. Many typos are repeated in the same way by many people.

Can't wait for the spam to start flowing from that list of users they are collecting. Of course Verisign will protect their customers from the spam. That'll be part of the deal with the spammers they sell to.



Current thread: