Forged Mail Headers
Discussion
Ok, we keep receiving dodgy emails supposedly from the same source. Here are the headers from the latest one:
*********************************************
Microsoft Mail Internet Headers Version 2.0
Received: from punt1.ex.eclipse.net.uk ([212.104.129.56]) by cerbera.girlings.local with Microsoft SMTPSVC(5.0.2195.6713);
Tue, 21 Jun 2005 17:21:17 +0100
Received: from mxa05.ex.eclipse.net.uk (unknown [212.104.129.144])
by punt1.ex.eclipse.net.uk (Postfix) with ESMTP id E072395F8
for <enquiries@heritageliving.co.uk>; Tue, 21 Jun 2005 17:17:52 +0100 (BST)
[b]Received: from heritageliving.co.uk (gateway.uniquedistribution.co.uk [195.224.115.178])[/b]
by mxa05.ex.eclipse.net.uk (Postfix) with ESMTP id 6055111B847
for <enquiries@heritageliving.co.uk>; Tue, 21 Jun 2005 17:17:51 +0100 (BST)
From: register@heritageliving.co.uk
To: enquiries@heritageliving.co.uk
Subject: *DETECTED* Online User Violation
*****************************************************
Heritageliving.co.uk is one of our own domains so obviously that part of the header is forged. However, is there anyway I can tell if the reverse DNS entry (in bold) is forged? The mails we recieve always have the same originating IP: gateway.uniquedistribution.co.uk [195.224.115.178].
I have sent an notification to the abuse address for the upstream provider of that domain anyway, but whether it will do any good or not I'm not sure.
Jamie
*********************************************
Microsoft Mail Internet Headers Version 2.0
Received: from punt1.ex.eclipse.net.uk ([212.104.129.56]) by cerbera.girlings.local with Microsoft SMTPSVC(5.0.2195.6713);
Tue, 21 Jun 2005 17:21:17 +0100
Received: from mxa05.ex.eclipse.net.uk (unknown [212.104.129.144])
by punt1.ex.eclipse.net.uk (Postfix) with ESMTP id E072395F8
for <enquiries@heritageliving.co.uk>; Tue, 21 Jun 2005 17:17:52 +0100 (BST)
[b]Received: from heritageliving.co.uk (gateway.uniquedistribution.co.uk [195.224.115.178])[/b]
by mxa05.ex.eclipse.net.uk (Postfix) with ESMTP id 6055111B847
for <enquiries@heritageliving.co.uk>; Tue, 21 Jun 2005 17:17:51 +0100 (BST)
From: register@heritageliving.co.uk
To: enquiries@heritageliving.co.uk
Subject: *DETECTED* Online User Violation
*****************************************************
Heritageliving.co.uk is one of our own domains so obviously that part of the header is forged. However, is there anyway I can tell if the reverse DNS entry (in bold) is forged? The mails we recieve always have the same originating IP: gateway.uniquedistribution.co.uk [195.224.115.178].
I have sent an notification to the abuse address for the upstream provider of that domain anyway, but whether it will do any good or not I'm not sure.
Jamie
Unix said:
root@Mook:~> host 195.224.115.178
178.115.224.195.IN-ADDR.ARPA domain name pointer gateway.uniquedistribution.co.uk
root@Mook:~> host gateway.uniquedistribution.co.uk
gateway.uniquedistribution.co.uk has address 195.224.115.178
inetnum: 195.224.115.176 - 195.224.115.183
netname: GX-UNIQUE
descr: Unique Distribution Ltd
descr: 2 Home Farme Barn
descr: Thrupp Lane
descr: Radley
descr: Oxfordshire
descr: OX14 3NG
country: GB
remarks: ------------------------------------------------------
remarks:
remarks: Please direct Abuse complaints to abuse@gxn.net
remarks: Complaints directed elsewhere may not be actioned.
remarks:
remarks: ------------------------------------------------------
Domain Name:
uniquedistribution.co.uk
Registrant:
Michael Richardson
Registrant's Address:
Beacon Marketing
Rose Business Estate
Marlow Bottom
Bucks
SL7 3ND
GB
Looks Valid, abuse address provided for your benefit.
Just firewall that IP if you need. most likely someones been hacked.
www.uniquedistribution.co.uk/
01235 557557
You could always call them and tell them (but I doubt they'd understand a word of it!)
GL
J
_dobbo_ said:
No, the IP in bold is the one that gave it to mxa05.ex.eclipse.net.uk, which in turn gave it to punt1.ex.eclipse.net.uk, which in turn gave it to cerbera.girlings.local. So the only IP that can be blocked is that of punt1, but if that's your main mail route, not the best idea...
aah indeed, didnt notice the line below.
Spam Blocker blocking that header line will suffice.
Rather than just putting my little comments in I could have actually taken the time to give a useful response! Apologies for this.
These emails are as far as I can see instances of virus infected email that is being sent (think it's MyTob) - hence the forged details. You could indeed block it using some anti-spam software on the server/client.
Ultimately though this is a reactive approach - tomorrow this virus or another will come from a different IP with a different subject. A better solution is to be proactive, so that either your server (or probably cheaper) your ISPs server blocks messages infected with Viruses. (or is it virii?
)
Alternatively, and much cheaper still is to get an anti-spam package that can block all types of attachment that can be dangerous - such as exe, vbs, scr, pif, com, bat, the list goes on.
These emails are as far as I can see instances of virus infected email that is being sent (think it's MyTob) - hence the forged details. You could indeed block it using some anti-spam software on the server/client.
Ultimately though this is a reactive approach - tomorrow this virus or another will come from a different IP with a different subject. A better solution is to be proactive, so that either your server (or probably cheaper) your ISPs server blocks messages infected with Viruses. (or is it virii?
) Alternatively, and much cheaper still is to get an anti-spam package that can block all types of attachment that can be dangerous - such as exe, vbs, scr, pif, com, bat, the list goes on.
The best solution I've found is to try and use web based mail. But I do prefer using a email client as emails/files are only one click away.
I suggest using Spampal.
This great utility will tag SPAM and provides great filtering options.
available from www.spampal.org I believe.
Good Luck.
I suggest using Spampal.
This great utility will tag SPAM and provides great filtering options.
available from www.spampal.org I believe.
Good Luck.
Server level recommends (for a limited IT budget):
Anti-Spam:
www.gfi.com/mes/
Ant-Virus: (uses mutiple scan engines updated daily)
www.gfi.com/mailsecurity/
ErnestM
Anti-Spam:
www.gfi.com/mes/
Ant-Virus: (uses mutiple scan engines updated daily)
www.gfi.com/mailsecurity/
ErnestM
It wasnt a filtering question as the mail in question does get filtered out by our AV filter. Also having an smtp stream direct from our ISP means I couldnt filter by originating IP anyway.
We were just receiveing rather a lot of them from the supposed same IP and I just wanted to contact them to let them know they may be compromised. I have contacted their IT Manager and they are virus scanning everything connected to their network. I just wanted to know if there was any definitive way of proving if a reverse DNS in the headers is legit or not.
I expect it is legit. The virus in question was only discovered a week ago so I suspect their AV definitions were not up-to-date and a machine on their network was compromised.
We were just receiveing rather a lot of them from the supposed same IP and I just wanted to contact them to let them know they may be compromised. I have contacted their IT Manager and they are virus scanning everything connected to their network. I just wanted to know if there was any definitive way of proving if a reverse DNS in the headers is legit or not.
I expect it is legit. The virus in question was only discovered a week ago so I suspect their AV definitions were not up-to-date and a machine on their network was compromised.
jamiet said:
It wasnt a filtering question as the mail in question does get filtered out by our AV filter. Also having an smtp stream direct from our ISP means I couldnt filter by originating IP anyway.
We were just receiveing rather a lot of them from the supposed same IP and I just wanted to contact them to let them know they may be compromised. I have contacted their IT Manager and they are virus scanning everything connected to their network. I just wanted to know if there was any definitive way of proving if a reverse DNS in the headers is legit or not.
I expect it is legit. The virus in question was only discovered a week ago so I suspect their AV definitions were not up-to-date and a machine on their network was compromised.
Unfortunately nothing is sacred in the headers - it could all be real or false, or somewhere in between.
Technically even the IP that connects to your server could have been faked, but that's MUCH harder than altering or fabricating headers.
Gassing Station | Computers, Gadgets & Stuff | Top of Page | What's New | My Stuff


