Re: Realisticness of header rearrangement

Laird Breyer <[email protected]> Wed, 7 Apr 2004 00:56:12 +1000
Newsgroups gmane.ietf.asrg.filtering
Message-ID <20040406145612.GA14719@ender>
On Apr 06 2004, Bill Yerazunis wrote:
> 
> Say a smart spammer sends an email that carries no spam payload, so it's
> otherwise acceptable.  This email actually _has_ a valid 
> Errors-to: address; the message also has an intentionally defective
> routing so that it bounces after acceptance.
> 
> Now the spammer has an example of an email header set that carries
> all of the "I am good" fingerprints. 
> 
> You need reasonably strong crypto to not be breakable easily at that point.
> 

Nice. Yet another way of fishing for information. Note however that
*this* attack is useless against the Received: timestamp defense, as
discussed in other parts of this thread. 

The spammer can fish for as many sample emails as he likes, because 
each such email will have a useless Received: timestamp. When he sends
his real spam, he has to predict the exact time which the SMTP server 
will prepend to that email after fully receiving it and processing
it. Only if the spammer gets that time exactly right will the spoof work.


-- 
Laird Breyer.