Forged Mail Headers
Author
Discussion

jamiet

Original Poster:

1,536 posts

282 months

Wednesday 22nd June 2005
quotequote all
Ok, we keep receiving dodgy emails supposedly from the same source. Here are the headers from the latest one:

*********************************************
Microsoft Mail Internet Headers Version 2.0

Received: from punt1.ex.eclipse.net.uk ([212.104.129.56]) by cerbera.girlings.local with Microsoft SMTPSVC(5.0.2195.6713);

Tue, 21 Jun 2005 17:21:17 +0100

Received: from mxa05.ex.eclipse.net.uk (unknown [212.104.129.144])

by punt1.ex.eclipse.net.uk (Postfix) with ESMTP id E072395F8

for <enquiries@heritageliving.co.uk>; Tue, 21 Jun 2005 17:17:52 +0100 (BST)

[b]Received: from heritageliving.co.uk (gateway.uniquedistribution.co.uk [195.224.115.178])[/b]

by mxa05.ex.eclipse.net.uk (Postfix) with ESMTP id 6055111B847

for <enquiries@heritageliving.co.uk>; Tue, 21 Jun 2005 17:17:51 +0100 (BST)

From: register@heritageliving.co.uk

To: enquiries@heritageliving.co.uk

Subject: *DETECTED* Online User Violation

*****************************************************

Heritageliving.co.uk is one of our own domains so obviously that part of the header is forged. However, is there anyway I can tell if the reverse DNS entry (in bold) is forged? The mails we recieve always have the same originating IP: gateway.uniquedistribution.co.uk [195.224.115.178].

I have sent an notification to the abuse address for the upstream provider of that domain anyway, but whether it will do any good or not I'm not sure.

Jamie

ErnestM

11,621 posts

297 months

Wednesday 22nd June 2005
quotequote all
Why not just block the IP's from the ISP?

ErnestM

JamieBeeston

9,294 posts

295 months

Wednesday 22nd June 2005
quotequote all
Unix said:

root@Mook:~> host 195.224.115.178
178.115.224.195.IN-ADDR.ARPA domain name pointer gateway.uniquedistribution.co.uk

root@Mook:~> host gateway.uniquedistribution.co.uk
gateway.uniquedistribution.co.uk has address 195.224.115.178

inetnum: 195.224.115.176 - 195.224.115.183
netname: GX-UNIQUE
descr: Unique Distribution Ltd
descr: 2 Home Farme Barn
descr: Thrupp Lane
descr: Radley
descr: Oxfordshire
descr: OX14 3NG
country: GB

remarks: ------------------------------------------------------
remarks:
remarks: Please direct Abuse complaints to abuse@gxn.net
remarks: Complaints directed elsewhere may not be actioned.
remarks:
remarks: ------------------------------------------------------

Domain Name:
uniquedistribution.co.uk

Registrant:
Michael Richardson

Registrant's Address:
Beacon Marketing
Rose Business Estate
Marlow Bottom
Bucks
SL7 3ND
GB



Looks Valid, abuse address provided for your benefit.

Just firewall that IP if you need. most likely someones been hacked.

www.uniquedistribution.co.uk/
01235 557557

You could always call them and tell them (but I doubt they'd understand a word of it!)

GL

J

_dobbo_

14,619 posts

278 months

Wednesday 22nd June 2005
quotequote all
Don't think firewalling the IP would work? By the time it arrives it's been through two other servers, so you can't block on the IP that's in bold above, since that never connects to your server. It's the topmost received header that's most recent - I assume this is your ISP?

darrent

630 posts

289 months

Wednesday 22nd June 2005
quotequote all
JamieBeeston said:

[quote=Unix]


Domain Name:
uniquedistribution.co.uk

Registrant:
Michael Richardson

Registrant's Address:
Beacon Marketing
Rose Business Estate
Marlow Bottom
Bucks
SL7 3ND
GB


J


I actually know Mike Richardson - called him but he has left the company!!!

_dobbo_

14,619 posts

278 months

Wednesday 22nd June 2005
quotequote all
No, the IP in bold is the one that gave it to mxa05.ex.eclipse.net.uk, which in turn gave it to punt1.ex.eclipse.net.uk, which in turn gave it to cerbera.girlings.local. So the only IP that can be blocked is that of punt1, but if that's your main mail route, not the best idea...

JamieBeeston

9,294 posts

295 months

Wednesday 22nd June 2005
quotequote all
_dobbo_ said:
No, the IP in bold is the one that gave it to mxa05.ex.eclipse.net.uk, which in turn gave it to punt1.ex.eclipse.net.uk, which in turn gave it to cerbera.girlings.local. So the only IP that can be blocked is that of punt1, but if that's your main mail route, not the best idea...



aah indeed, didnt notice the line below.

Spam Blocker blocking that header line will suffice.

_dobbo_

14,619 posts

278 months

Wednesday 22nd June 2005
quotequote all
Rather than just putting my little comments in I could have actually taken the time to give a useful response! Apologies for this.

These emails are as far as I can see instances of virus infected email that is being sent (think it's MyTob) - hence the forged details. You could indeed block it using some anti-spam software on the server/client.

Ultimately though this is a reactive approach - tomorrow this virus or another will come from a different IP with a different subject. A better solution is to be proactive, so that either your server (or probably cheaper) your ISPs server blocks messages infected with Viruses. (or is it virii? )

Alternatively, and much cheaper still is to get an anti-spam package that can block all types of attachment that can be dangerous - such as exe, vbs, scr, pif, com, bat, the list goes on.

RameshUK

595 posts

292 months

Wednesday 22nd June 2005
quotequote all
The best solution I've found is to try and use web based mail. But I do prefer using a email client as emails/files are only one click away.

I suggest using Spampal.

This great utility will tag SPAM and provides great filtering options.

available from www.spampal.org I believe.

Good Luck.

ErnestM

11,621 posts

297 months

Thursday 23rd June 2005
quotequote all
Server level recommends (for a limited IT budget):

Anti-Spam:
www.gfi.com/mes/

Ant-Virus: (uses mutiple scan engines updated daily)
www.gfi.com/mailsecurity/


ErnestM

jamiet

Original Poster:

1,536 posts

282 months

Friday 24th June 2005
quotequote all
It wasnt a filtering question as the mail in question does get filtered out by our AV filter. Also having an smtp stream direct from our ISP means I couldnt filter by originating IP anyway.

We were just receiveing rather a lot of them from the supposed same IP and I just wanted to contact them to let them know they may be compromised. I have contacted their IT Manager and they are virus scanning everything connected to their network. I just wanted to know if there was any definitive way of proving if a reverse DNS in the headers is legit or not.

I expect it is legit. The virus in question was only discovered a week ago so I suspect their AV definitions were not up-to-date and a machine on their network was compromised.

_dobbo_

14,619 posts

278 months

Friday 24th June 2005
quotequote all
jamiet said:
It wasnt a filtering question as the mail in question does get filtered out by our AV filter. Also having an smtp stream direct from our ISP means I couldnt filter by originating IP anyway.

We were just receiveing rather a lot of them from the supposed same IP and I just wanted to contact them to let them know they may be compromised. I have contacted their IT Manager and they are virus scanning everything connected to their network. I just wanted to know if there was any definitive way of proving if a reverse DNS in the headers is legit or not.

I expect it is legit. The virus in question was only discovered a week ago so I suspect their AV definitions were not up-to-date and a machine on their network was compromised.


Unfortunately nothing is sacred in the headers - it could all be real or false, or somewhere in between.

Technically even the IP that connects to your server could have been faked, but that's MUCH harder than altering or fabricating headers.