Re: Spamcop failing to detect true originating IP

wskrispy <[email protected]>
Newsgroups gmane.mail.spam.spamcop.help
Organization SpamCop
Message-ID <[email protected]>
N. Miller wrote:
> On Wed, 13 Jul 2005 13:44:00 -0400, wskrispy wrote:
> 
> 
>> From one vantage point I'm almost tempted to say that, well, it looks 
>>like the spammer has outwitted Spamcop. You say "there is no way that SC 
>>has (can) determine the source of the spam". If that's so, wouldn't you 
>>agree the spammer has found a spoofing method that confounds Spamcop?
> 
> 
> No. Spammers use spoofed "HELO" strings all of the time. I see a lot of
> attempts to dump email on my server with "HELO mail.yahoo.com", followed by
> the connecting IP address; that IP address is never a yahoo.com IP address.
> The important point to note is that the spammer can't control the IP
> address which my MX is seeing. If the MX is properly configured, it will
> show the connecting IP address; at that point, SpamCop can proceed. But
> whether that IP address is present, or not, in the headers is beyond the
> control of the spammer. The responsibility to log the IP addresses of the
> incoming connections lies squarely on the receiving email server.
> Therefore, it is your own email system which is outwitting SpamCop. It
> would also outwit Sam Spade, and me.
> 
> 
>>This server is a Virtual Private Server under a hosting company. I 
>>administer it for an artist's studio. I'm a retired programmer, not an 
>>Admin. But I know enough to get LANs up and running and to provide basic 
>>WWW/FTP/Email services and troubleshoooting for small businesses. As far 
>>as I can tell, this server is configured with typical options and its 
>>primary mailer program (Exim) is not writing anything unusual to emails, 
>>nor deleting or scrambling headers.
> 
> 
> It is, however, omitting certain information which is available to it, and
> could be included; namely, the IP address of the incoming connection.
> 

Hold on a sec Ellen and N. Miller-- if you look at the entire message at 
tracker 
http://www.spamcop.net/sc?id=z785186974zfb5c4d04f5694f362a90b200bac251bfz;action=display 
  you will see that in the header block below the SA Content Analysis 
there is a third Received header which does in fact identify the 
connecting IP (85.40.108.210). Why didn't Spamcop use this and proceed?

Ellen said "For some reason and for some spams, your server will print 2 
received headers as above rather than showing the connecting IP as it 
does for other spams". This is not so. All these spams have this header 
block eventually showing the connecting IP.

--
wsk
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.