Re: [Asrg] Some data on the validity of MAIL FROM addresses

Yakov Shafranovich <research@solidmatrix.com> Wed, 21 May 2003 19:41 UTC

Received: from www1.ietf.org (ietf.org [132.151.1.19] (may be forged)) by ietf.org (8.9.1a/8.9.1a) with ESMTP id PAA06022 for <asrg-archive@odin.ietf.org>; Wed, 21 May 2003 15:41:14 -0400 (EDT)
Received: (from mailnull@localhost) by www1.ietf.org (8.11.6/8.11.6) id h4LJ8As10896 for asrg-archive@odin.ietf.org; Wed, 21 May 2003 15:08:10 -0400
Received: from ietf.org (odin.ietf.org [132.151.1.176]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h4LJ8AB10893 for <asrg-web-archive@optimus.ietf.org>; Wed, 21 May 2003 15:08:10 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id PAA05977; Wed, 21 May 2003 15:40:44 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1]) by ietf-mx with esmtp (Exim 4.12) id 19IZQo-00029I-00; Wed, 21 May 2003 15:39:22 -0400
Received: from ietf.org ([132.151.1.19] helo=www1.ietf.org) by ietf-mx with esmtp (Exim 4.12) id 19IZQo-00029F-00; Wed, 21 May 2003 15:39:22 -0400
Received: from www1.ietf.org (localhost.localdomain [127.0.0.1]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h4LIv3B09363; Wed, 21 May 2003 14:57:03 -0400
Received: from ietf.org (odin.ietf.org [132.151.1.176]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h4LIuWB09299 for <asrg@optimus.ietf.org>; Wed, 21 May 2003 14:56:32 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id PAA05038 for <asrg@ietf.org>; Wed, 21 May 2003 15:29:07 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1]) by ietf-mx with esmtp (Exim 4.12) id 19IZFZ-0001r2-00 for asrg@ietf.org; Wed, 21 May 2003 15:27:45 -0400
Received: from 000-246-401.area7.spcsdns.net ([68.27.202.22] helo=68.27.202.22 ident=trilluser) by ietf-mx with smtp (Exim 4.12) id 19IZFW-0001qw-00 for asrg@ietf.org; Wed, 21 May 2003 15:27:44 -0400
Message-Id: <5.2.0.9.2.20030521152841.00bba2d0@solidmatrix.com>
X-Sender: research@solidmatrix.com
X-Mailer: QUALCOMM Windows Eudora Version 5.2.0.9
To: asrg@ietf.org
From: Yakov Shafranovich <research@solidmatrix.com>
Subject: Re: [Asrg] Some data on the validity of MAIL FROM addresses
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format="flowed"
X-MimeHeaders-Plugin-Info: v2.03.00
X-GCMulti: 1
Sender: asrg-admin@ietf.org
Errors-To: asrg-admin@ietf.org
X-BeenThere: asrg@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=unsubscribe>
List-Id: Anti-Spam Research Group - IRTF <asrg.ietf.org>
List-Post: <mailto:asrg@ietf.org>
List-Help: <mailto:asrg-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=subscribe>
List-Archive: <https://www1.ietf.org/pipermail/asrg/>
Date: Wed, 21 May 2003 15:28:44 -0400

At 11:32 AM 5/21/2003 -0700, you wrote:

>BTW, it would be instructive if someone who has access to one, and the
>know-how to decompile it, could examine its sending code and indicate
>whether it uses randomly-generated addresses, or a static list of existing
>ones loaded from a config file, for the addresses used in the MAIL FROM
>SMTP command and From: header.

I think it would me helpful if we can get all the information we can out of 
such tools. Is there anyone that can provide such information or perhaps 
have some "white-hat" friends that do?

Yakov  

_______________________________________________
Asrg mailing list
Asrg@ietf.org
https://www1.ietf.org/mailman/listinfo/asrg