UGN Security Forums
My ProfileMember DirectoryLogin
Search our ForumsView our FAQView our Site Rules
View our CalendarView our Active TopicsGo to our Main Page

UGN Security Store
 

Network Sites UGN Security, The GoNix Initiative, Elite Web Gamers, Back of the Web, EveryDay Helper, VNC Web Design & Development
July
Su M Tu W Th F Sa
1 2 3 4 5
6 7 8 9 10 11 12
13 14 15 16 17 18 19
20 21 22 23 24 25 26
27 28 29 30 31
Sponsored Links
Latest Postings
Latest Reviews
Topic Options
Rate This Topic
#6308 - 10/03/03 03:53 AM mx1 - yahoo and mail bug
bosky101 Offline
Junior Member

Registered: 10/01/03
Posts: 59
Loc: india
hi im a newbie here...and the first thing i learned wa the
mx1.mail.hotmail.com
mx1.mail.yahoo.com
vulnerabilty...
So the Qestion is ...WHY arnt theydoing anything about it ...dont tell me they dont KNOW.. lol

anyway..is there anyway way i can get the ip of the person i send an wmail to / or get an email from ? using patches ..or remote exes.?
_________________________
"it is the question ...that drives the answer..."
Keep Clicking,
Bosky

Top
Sponsored Links
      
#6309 - 10/03/03 06:02 AM Re: mx1 - yahoo and mail bug
sinetific Offline
nobody

Registered: 03/02/02
Posts: 815
Loc: Ann Arbor
Are you refering to being able to forge fake from headers on an email? That is not a vulnerablity. It is the functionality of the POP3 protocol, that is why they dont do anything about it. You need to be able to specify who the letter is from and if you notice it doesnt matter if it's forged, you can still check the header and see the address of the sender. Places like yahoo and hotmail need to open these servers up to everyone because thier client base comes from everywhere. When it comes to ISP POP3 accounts the disable access to thier POP3 servers to everyone except clients on thier network or computers on thier netblock.

Top
#6310 - 10/03/03 06:48 AM Re: mx1 - yahoo and mail bug
jonconley Offline
UGN Super Poster

Registered: 10/08/02
Posts: 955
Loc: Merrill, IA, USA
You can get the IP of the person sending a mail from the mail headers themselves. I don't know the exact title of the header, but I answered a question like this before and SR was able to come along and give the details So for now, you will have to look yourself, but it shouldn't be too hard to figure out.

Didn't know if that is what sin was talking about in reference to the "address" or if he was referring to the email addy.

No, I won't search for it, I could but so could you.

Top
#6311 - 10/03/03 06:57 AM Re: mx1 - yahoo and mail bug
sinetific Offline
nobody

Registered: 03/02/02
Posts: 815
Loc: Ann Arbor
Oh i was refering to seeing the IP address of the sender in the email header that you can view in the properties of the email or in other places depending on the client you use. But you will be able to tell if the IP corresponds to the 'from' address.

Top
#6312 - 10/03/03 09:41 AM Re: mx1 - yahoo and mail bug
SilentRage Offline
DollarDNS Owner

Registered: 03/04/02
Posts: 1273
Loc: OH, USA
The last "Recieved" header (and consequently the first "Recieved" prepended to the email) in the email headers is information about the source of the email including the source IP address.
_________________________
Domain Registration, Hosting, Management
http://www.dollardns.net

Top
#6313 - 10/04/03 02:37 AM Re: mx1 - yahoo and mail bug
bosky101 Offline
Junior Member

Registered: 10/01/03
Posts: 59
Loc: india
thnx a lot guys... gee sinetific , guess i need to read more on protocols i guess ...

ok...i jus found that Outlook has an option to read email headers apart from the message properties . is this what SR is talking about...the checkbox with the "internet header ,show last recieved "

anyway..so ,reading the email headers reveal the ip address...hmmm intersting...but what if ,they use some "remailing" facility like :
A4proxy ( http://www.inetprivacy.com/a4proxy/ )
or some other proxy, which strips out all original email headers and info about your location and IP address, and then sends the message to its final destination...
and i guess realised that i guess i wont be able to send an email back to them coz ....itsNOT thier legitimate email anyway...so they cant check it rite...waht u think...ilemme try seraching on "how to mail to an ip adress instead " ..
thnx again
_________________________
"it is the question ...that drives the answer..."
Keep Clicking,
Bosky

Top

Moderator:  Infinite 
Featured Member
Registered: 03/05/02
Posts: 9
Forum Stats
2145 Members
46 Forums
33451 Topics
68618 Posts

Max Online: 1567 @ 04/25/10 10:20 AM
Top Posters
UGN Security 26614
Gremelin 7192
§intå× 3255
SilentRage 1273
Ice 1146
pergesu 1136
Infinite 1041
jonconley 955
Girlie 908
unreal 860
Newest Members
Jimmie Menon, fghijk435948, Devo60, ali, lavos
2147 Registered Users
Who's Online
0 registered (), 707 Guests and 325 Spiders online.
Key: Admin, Global Mod, Mod
Latest News


Donate
  Get Firefox!
Get FireFox!