Security Incidents mailing list archives

Re: blind forwards


From: brock.norvell () IFACTOR-E COM (Brock Norvell)
Date: Thu, 29 Jun 2000 20:44:02 GMT


Original Message <<<<<<<<<<<<<<<<<<

On 6/28/00, 2:13:48 PM, Keith McCammon <kmccammon () TIDALWAVE NET> wrote 
regarding blind forwards:

Hey all,

This may or may not be the right list for this.  It doesn't seem to fit
nicely anywhere.  However, we're investigating this at work, and I know
someone out there knows the answer.  (An incident I suppose)

I'm curious to find out how one could go about analyzing an e-mail to 
find
out if it is being intercepted upstream before it reaches the intended
recipient.  For example, with some e-mail servers, a file can be placed 
in
the user's mailbox on the server that will "blind" forward any incoming 
mail
to a given address.

SMTP Server --> Recipient's Mail Server--> USER-X (blind) and INTENDED-USER
(as usual)

I'd imagine that this is highly illegal at the upstream level under most
circumstances; and I know there's a way to find out if this type of 
snooping
is taking place.  Anyone?  Anyone?

Keith

Depending upon who your ISP or upstream is, and what their TOS (Terms of 
Service) are, this may not be illegal at all, however, IANAL. As for the 
blind copy, if it's done right, there's no way you could determine from 
the headers whether or not it's being done. Access to the mail server's 
log could provide with that information tho.

Brock


Current thread: