RE: [Asrg] Some data on the validity of MAIL FROM addresses

"Eric D. Williams" <eric@infobro.com> Thu, 22 May 2003 02:40 UTC

Received: from www1.ietf.org (ietf.org [132.151.1.19] (may be forged)) by ietf.org (8.9.1a/8.9.1a) with ESMTP id WAA16133 for <asrg-archive@odin.ietf.org>; Wed, 21 May 2003 22:40:41 -0400 (EDT)
Received: (from mailnull@localhost) by www1.ietf.org (8.11.6/8.11.6) id h4M27ju08299 for asrg-archive@odin.ietf.org; Wed, 21 May 2003 22:07:45 -0400
Received: from ietf.org (odin.ietf.org [132.151.1.176]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h4M27jB08296 for <asrg-web-archive@optimus.ietf.org>; Wed, 21 May 2003 22:07:45 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id WAA16111; Wed, 21 May 2003 22:40:10 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1]) by ietf-mx with esmtp (Exim 4.12) id 19Ifyj-0004aa-00; Wed, 21 May 2003 22:38:49 -0400
Received: from ietf.org ([132.151.1.19] helo=www1.ietf.org) by ietf-mx with esmtp (Exim 4.12) id 19Ifyi-0004aX-00; Wed, 21 May 2003 22:38:48 -0400
Received: from www1.ietf.org (localhost.localdomain [127.0.0.1]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h4M1xqB07186; Wed, 21 May 2003 21:59:52 -0400
Received: from ietf.org (odin.ietf.org [132.151.1.176]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h4M1w0B07088 for <asrg@optimus.ietf.org>; Wed, 21 May 2003 21:58:00 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id WAA15997 for <asrg@ietf.org>; Wed, 21 May 2003 22:30:26 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1]) by ietf-mx with esmtp (Exim 4.12) id 19IfpI-0004Yk-00 for asrg@ietf.org; Wed, 21 May 2003 22:29:04 -0400
Received: from black.infobro.com ([63.71.25.39] helo=infobro.com) by ietf-mx with smtp (Exim 4.12) id 19IfpH-0004YM-01 for asrg@ietf.org; Wed, 21 May 2003 22:29:04 -0400
Received: from red (unverified [207.199.136.153]) by infobro.com (EMWAC SMTPRS 0.83) with SMTP id <B0002562155@infobro.com>; Wed, 21 May 2003 22:28:46 -0400
Received: by localhost with Microsoft MAPI; Wed, 21 May 2003 22:28:46 -0400
Message-ID: <01C31FE8.57BE0310.eric@infobro.com>
From: "Eric D. Williams" <eric@infobro.com>
To: 'Justin Mason' <jm@jmason.org>, Yakov Shafranovich <research@solidmatrix.com>
Cc: "asrg@ietf.org" <asrg@ietf.org>
Subject: RE: [Asrg] Some data on the validity of MAIL FROM addresses
Organization: Information Brokers, Inc.
X-Mailer: Microsoft Internet E-mail/MAPI - 8.0.0.4211
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Content-Transfer-Encoding: 7bit
Sender: asrg-admin@ietf.org
Errors-To: asrg-admin@ietf.org
X-BeenThere: asrg@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=unsubscribe>
List-Id: Anti-Spam Research Group - IRTF <asrg.ietf.org>
List-Post: <mailto:asrg@ietf.org>
List-Help: <mailto:asrg-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=subscribe>
List-Archive: <https://www1.ietf.org/pipermail/asrg/>
Date: Wed, 21 May 2003 22:01:44 -0400
Content-Transfer-Encoding: 7bit
Content-Transfer-Encoding: 7bit

On Wednesday, May 21, 2003 2:32 PM, Justin Mason [SMTP:jm@jmason.org] wrote:
8<...>8
> BTW, it would be instructive if someone who has access to one, and the
> know-how to decompile it, could examine its sending code and indicate
> whether it uses randomly-generated addresses, or a static list of existing
> ones loaded from a config file, for the addresses used in the MAIL FROM
> SMTP command and From: header.

You nailed it. That's where I am coming from exactly, I can do the forensics, 
or aid in decompilation and disassembly of it, however the key is to gain 
possession of some known working examples, and unfortunately (or fortunately 
for me) I have not had to 'deal with the zombies'.  In any event, if some code 
should become available I would be interested in developing the 'spamware' 
taxonomy.  Thanks for the search pointers J.

-e
_______________________________________________
Asrg mailing list
Asrg@ietf.org
https://www1.ietf.org/mailman/listinfo/asrg