Re: [EXIM] IP spoofing

Top Page
Delete this message
Reply to this message
Author: Jeffrey Goldberg
Date:  
To: Marilyn Davis
CC: exim-users, zapa
New-Topics: Log format, Unrelated but started as: Re: [EXIM] IP spoofing
Subject: Re: [EXIM] IP spoofing
On Sat, 8 May 1999, Jeffrey Goldberg wrote:

> First there is a shocking number of hosts sending mail without proper
> reverse (PTR) lookups. So there are legitimate, but misconfigured,
> mailhubs for which you can't map from IP address to any domain name.


I just checked yesterday's logs on one hub and found that 729 messages
were from such hosts, although often just a few such hosts produced a
number of such messages.

Here is a sample log entry (broken for readability and slightly edited)
from a host that produced about 20 of these.

1999-05-07 00:16:03 10fXN4-0003tl-00 <=
Microsoft_011876@???
H=(cpitgmsgd10.NEWSWIRE.MICROSOFT.COM) [207.46.134.22]
P=esmtp S=4779
T="UK Local News- Announcing Microsoft 2000"
from <Microsoft_011876@???>
for [...]

Another big offender is lyris.com

-j
-- 
Jeffrey Goldberg                +44 (0)1234 750 111 x 2826
 Cranfield Computer Centre      FAX         751 814
 J.Goldberg@???     http://WWW.Cranfield.ac.uk/public/cc/cc047/
Relativism is the triumph of authority over truth, convention over justice.



--
*** Exim information can be found at http://www.exim.org/ ***