+++++++++++Backtracking EMAIL Messages+++++++++++++
Tracking email back to its source: Twisted Evil
cause i hate spammers... Evil or Very Mad
Ask most people how they determine who sent them an email message and the response is almost universally, "By the From line."
Unfortunately this symptomatic of the current confusion among internet users as to where particular messages come from and who is spreading spam and viruses.
The "From" header is little more than a courtesy to the person receiving the message. People spreading spam and viruses are rarely courteous.
In short, if there is any question about where a particular email message came from the safe bet is to assume the "From" header is forged.
So how do you determine where a message actually came from? You have to understand how email messages are put together in order to backtrack an email message.
SMTP is a text based protocol for transferring messages across the internet.
A series of headers are placed in front of the data portion of the message. By examining the headers you can usually backtrack a message to the source network, sometimes the source host.
A more detailed essay on reading email headers can be found .
If you are using Outlook or Outlook Express you can view the headers by right clicking on the message and selecting properties or options.
Below are listed the headers of an actual spam message I received. I've changed my email address and the name of my server for obvious reasons.
I've also double spaced the headers to make them more readable.
Return-Path: 17 February 2010
Backtracking EMAIL Messages
+++++++++++Backtracking EMAIL Messages+++++++++++++
Tracking email back to its source: Twisted Evil
cause i hate spammers... Evil or Very Mad
Ask most people how they determine who sent them an email message and the response is almost universally, "By the From line."
Unfortunately this symptomatic of the current confusion among internet users as to where particular messages come from and who is spreading spam and viruses.
The "From" header is little more than a courtesy to the person receiving the message. People spreading spam and viruses are rarely courteous.
In short, if there is any question about where a particular email message came from the safe bet is to assume the "From" header is forged.
So how do you determine where a message actually came from? You have to understand how email messages are put together in order to backtrack an email message.
SMTP is a text based protocol for transferring messages across the internet.
A series of headers are placed in front of the data portion of the message. By examining the headers you can usually backtrack a message to the source network, sometimes the source host.
A more detailed essay on reading email headers can be found .
If you are using Outlook or Outlook Express you can view the headers by right clicking on the message and selecting properties or options.
Below are listed the headers of an actual spam message I received. I've changed my email address and the name of my server for obvious reasons.
I've also double spaced the headers to make them more readable.
Return-Path:
Subscribe to:
Post Comments (Atom)

0 comments:
Post a Comment