PaulDotCom mailing list archives

Spoofing emails


From: jim.halfpenny at gmail.com (Jim Halfpenny)
Date: Thu, 14 May 2009 08:19:30 +0100

2009/5/14 Noah <1giglimit at gmail.com>

If it is an SMTP Server that is accepting outgoing mail without
authentication, and you are sending from a domain that it accepts,

Isn't it possible to just use an e-mail client, say Outlook Express, and
change the Reply Address?

- Noah


Quite right. That's how I used to spoof emails in the days of way back
(1995) when University mail relays were wonderfully permissive. Never
underestimate the amount of trust that end users put into the From: field;
I've seen people believe the most unlikely of stories because of who an
email purported to be from.

Jim
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://mail.pauldotcom.com/pipermail/pauldotcom/attachments/20090514/1514365b/attachment.htm 


Current thread: