SPAMCOP HOME · SPAMCOP FAQ · NEWSGROUPS · FORUM FAQ · WEBMAIL · SSL WEBMAIL · SPAMCOPWIKI


 Other words, data, places -->  SpamCop Pages V  FAQs & Words V  Newsgroups V  WebMail V  News-Recent Stuff V   Poll on menu

------>------> Latest and Current Announcements <------<------

Welcome Guest ( Log In | Register )

> This is a User to User Support Forum

The primary mode of support here is peer-to-peer, meaning users helping other users. (please remember this at all times!)
Another try:
This forum is composed of people who have used spamcop and those who are learning about anti-spam efforts.

 
Reply to this topicStart new topic
> Analyzing header, What adress is it sent TO?
ZoRaC
post Sep 19 2006, 05:34 PM
Post #1


Newbie
*

Group: Members
Posts: 1
Joined: 19-September 06
Member No.: 6700



Since I use a "catch-all" adress on my domain, I want to be able to know what adress the spammer have sent the email TO, so that I can deactivate that perticular email on my server.

I thought the "Delivered-to" in the header would tell me this, but it seems it don't.
Can the spammer spoof this part of the header?
Any other way to find out?

Best regards,
Sven-Ove
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
dra007
post Sep 19 2006, 05:40 PM
Post #2


Been There
Group Icon

Group: Memberp
Posts: 1413
Joined: 18-March 04
Member No.: 777



What you are calling for is tantamount to listwashing. Spammers spoof everything except for the IP of injection. They often hide the real recipients in bcc and since they use dictionary attacks many the Deliver to: are bogus.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Wazoo
post Sep 19 2006, 07:30 PM
Post #3


What Life?
Group Icon

Group: Forum Admin
Posts: 12536
Joined: 22-January 04
From: Iowa
Member No.: 18



QUOTE(ZoRaC @ Sep 19 2006, 05:34 PM) *
Since I use a "catch-all" adress on my domain, I want to be able to know what adress the spammer have sent the email TO, so that I can deactivate that perticular email on my server.

?????

catch-all typically means 'nothing is defined for specific accounts' ....
therefore "deactivate that specific account" doesn't really make a lot of sense.

add that to the many and various ways e-mail addresses are 'created' by spammers, this seems like a losing game .. why not simply define certain accounts, reject anything else?
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
DavidT
post Sep 20 2006, 12:47 AM
Post #4


Been There
Group Icon

Group: Memberp
Posts: 1897
Joined: 28-January 04
Member No.: 63



QUOTE(ZoRaC @ Sep 19 2006, 03:34 PM) *
Since I use a "catch-all" adress on my domain

Sorry, but that's really a bad idea. I strongly recommend that you set up specific aliases/forwards for all desired addresses. Here's a quote from JT, the admin of the SpamCop email system:

QUOTE
We really discourage catch-all domains like you have set up because you end up receiving hundreds or thousands of spams that could have been trivially rejected just by asking your domain host to only accept valid email addresses. Catch-alls were fine 10 years ago, but aren't any more.


DT
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
showker
post Oct 3 2006, 02:14 PM
Post #5


Member
**

Group: Members
Posts: 99
Joined: 22-October 04
Member No.: 2909



QUOTE(dra007 @ Sep 19 2006, 06:40 PM) *
Spammers spoof everything except for the IP of injection.

So -- can you illustrate WHAT the "IP of injection" is ???

And, is that the IP one would BLOCK at server level?
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
dbiel
post Oct 3 2006, 02:37 PM
Post #6


Been There
Group Icon

Group: Membersph
Posts: 2453
Joined: 20-February 04
From: San Gabriel Valley CA USA (Los Angeles)
Member No.: 447



QUOTE(showker @ Oct 3 2006, 12:14 PM) *
So -- can you illustrate WHAT the "IP of injection" is ???
And, is that the IP one would BLOCK at server level?
Maybe the best way to start is to look at how mail travels through the internet.
Every time a server receives a mail message it knows the IP address that it came from by the packet header (not the email header)
When the server forwards the message it should add to the email header the information (including IP address) of where the message came from and where it is going to be sent to.
If a spammer has control of the server the recorded IP address can be forged along with any other recorded data.
The first properly configured mail server that receives the message out side of the control of the spammer can be considered the injection point (the point that the message enters the "internet") Anything prior to that point could be considered intranet regardless of the fact that it may be using internet connections. Zombie computers are actually a part of the Spammers intranet as they have control over them.


--------------------
This forum is a user support forum. The Moderators and Forum Admin are volunteers (not paid) and have no special direct relationship with SpamCop.net.
If you have been unable to receive the assistance you need here please see How To Contact SpamCop Staff
Thank you for your participation in our peer to peer, user based forums.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
MikeRG
post Oct 17 2006, 05:20 AM
Post #7


Member
**

Group: Members
Posts: 14
Joined: 25-May 04
Member No.: 1666



QUOTE(DavidT @ Sep 20 2006, 12:47 AM) *

Sorry, but that's really a bad idea. I strongly recommend that you set up specific aliases/forwards for all desired addresses. Here's a quote from JT, the admin of the SpamCop email system:
DT

(I am a domain owner using a hosting provider.)

I am currently Using Catchall and it has worked well in the past, but, with the devious methods that spammers are now using to obtain mail lists I am beginning to realise the error of my ways. Currently receiving an average of 214 spams per day sent to Invented, harvested and immorally (if not illegally) passed on addresses. All to ***[at]mydomain.xyz.
Many that use a legitimate prefix and add one or two characters to it.

Like many others, I originally used catchall so that when I needed to supply an email address on line, I used part of their name as the prefix. That way I would know if they had passed it on to spammers.
The trouble is that over the last 10 years or so, I have given out many different addresses that I have not kept track of.

I am currently reporting the 214 spams per day (137 today and its only 10:15am), and analysing the Sent To addresses so that I can add the genuine ones as separate pop3 accounts, eventually eliminating the need for catchall.

Some statistics that you may (or may not) find interesting.

Using 1392 reported spams (6.5 days)
My interpretation of the way that Email addresses originated
Harvested.........................13%
Passed on.........................67%
Invented...........................20%

Spammed addresses..........27 (***[at]mydomain)
Domains Received from....475 (***[at]anydomain)
. . . . . . yahoo[dot]com.......99 = (8.6%) Top culprit
. . . . . . fastmail[dot]ca.......17 = (1.5%) Second culprit


These are genuine as of 10:27am Oct-17-2006 (GMT)

This is why I now only give out my Hotmail email address to On line requests. Hotmail accounts being free, I may open a few more and use them the same way. (IMG:style_emoticons/default/smile.gif)

When I stop using my catchall facility, what should I do with rejected mail?
Bounce it
or
Delete it
These are the two choices that my host offers.

I understand that to bounce could cause problems for innocent victims of spammers using false Sent From addresses and increases traffic. To delete, will not inform the sender that this address does not exist and they will still keep sending.

I hope the stats help.
Thanks and regards to all
~Mike~

This post has been edited by MikeRG: Oct 17 2006, 05:23 AM
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Miss Betsy
post Oct 17 2006, 07:50 AM
Post #8


T-shirt wearing out
Group Icon

Group: Membersph
Posts: 3332
Joined: 2-February 04
Member No.: 174



QUOTE(showker @ Oct 3 2006, 03:14 PM) *

So -- can you illustrate WHAT the "IP of injection" is ???

And, is that the IP one would BLOCK at server level?

Actually, I thought that the only IP address that couldn't be spoofed is the IP address that your ISP receives the email from (because they get it from the 'packet' not the headers).

After that, one needs to be able to distinguish whether the header line was added by a legitimate server or not. That's what the parser does by checking DNS, etc. A human reading the same header lines may be able to see things the parser doesn't in complicated cases. However, the parser does it much faster than a human can for most email - which is why people use spamcop reporting services. And then there are others who don't understand headers who use spamcop because they can't read headers.

If the parser (or a human) come to a header line that doesn't seem to be real, then the header line before that (tested to be a real IP address) is considered the 'injection' IP address and the place to send reports. Intranet (servers passing email within its network) are not something that an outsider can test so, in most cases, when the parser comes to a line it can't test, it finds the computer where the spam was 'injected' into the internet.

That's a layman's explanation. There are all kinds of details that I left out (or perhaps not properly described).

Miss Betsy


--------------------
an almost new internet user
if you don't think your post has been answered sufficiently, please email service[at]admin.spamcop.net
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
turetzsr
post Oct 18 2006, 06:38 PM
Post #9


T-shirt wearing out
Group Icon

Group: Membersph
Posts: 3575
Joined: 26-January 04
From: Michigan USA
Member No.: 59



QUOTE(MikeRG @ Oct 17 2006, 06:20 AM) *
<snip>
When I stop using my catchall facility, what should I do with rejected mail?
Bounce it
or
Delete it
These are the two choices that my host offers.
...FWIW, my choice would be option 3: find a provider that rejects with a 500-level message or accepts it but allows you to direct it to a separate inbox. In the meantime, of the two choices you have, IMHO a delete would be the choice of a better netizen.


--------------------
..Regards,
...Steve T

...A Happy SpamCop.net user (not an employee)
...Please avoid replying via e-mail, as it is not secure
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
DavidT
post Oct 18 2006, 06:48 PM
Post #10


Been There
Group Icon

Group: Memberp
Posts: 1897
Joined: 28-January 04
Member No.: 63



QUOTE(MikeRG @ Oct 17 2006, 03:20 AM) *
I am currently reporting the 214 spams per day (137 today and its only 10:15am), and analysing the Sent To addresses so that I can add the genuine ones as separate pop3 accounts, eventually eliminating the need for catchall.

I went through that painful process a few years ago, and might have missed a few, but oh well.

However, I don't understand why you'd want to create unique POP3 boxes for each of the many addresses you've "made up" for use with vendors, etc. If you're the only one who needs to receive those messages, you should be able to set up "aliases" that forward the special addresses wherever you want, such as collecting them all into your main POP account, or some combination of those techniques, if you want to have some stuff collect and then POP it separately. I have hundreds of aliases, but only a few POP accounts.

DT
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

Reply to this topicStart new topic
2 User(s) are reading this topic (2 Guests and 0 Anonymous Users)
0 Members:

 

- Lo-Fi Version Time is now: 22nd November 2009 - 02:35 AM