Re: Realisticness of header rearrangement
Laird Breyer <[email protected]> Wed, 7 Apr 2004 00:56:12 +1000
| Newsgroups | gmane.ietf.asrg.filtering |
|---|---|
| Message-ID | <20040406145612.GA14719@ender> |
On Apr 06 2004, Bill Yerazunis wrote: > > Say a smart spammer sends an email that carries no spam payload, so it's > otherwise acceptable. This email actually _has_ a valid > Errors-to: address; the message also has an intentionally defective > routing so that it bounces after acceptance. > > Now the spammer has an example of an email header set that carries > all of the "I am good" fingerprints. > > You need reasonably strong crypto to not be breakable easily at that point. > Nice. Yet another way of fishing for information. Note however that *this* attack is useless against the Received: timestamp defense, as discussed in other parts of this thread. The spammer can fish for as many sample emails as he likes, because each such email will have a useless Received: timestamp. When he sends his real spam, he has to predict the exact time which the SMTP server will prepend to that email after fully receiving it and processing it. Only if the spammer gets that time exactly right will the spoof work. -- Laird Breyer.