Help - Search - Members - Calendar
Full Version: Wrongly identified origin?
hsc message board > Main > hsc Software Support
Tifferg


I ran the spam mail below through both SmartWhois and SpamX v1.27a and as you can see, SW identified the originator as Verizon whilst SpamX says Telenor.

I've just put it through 1.2.6 to check and that correctly identifies Verizon. Guess I broke it again rolleyes.gif



QUOTE
ABUSE@NOC.UK.TELENOR.NET;

Email Abuse Complaint
Here is the SMTP information.

SMTP Info Start ====================================

Return-Path: <c_hmoreno_wc@standitalia.it>
Delivered-To: spamcop-net-tifferg@spamcop.net
Received: (qmail 27876 invoked from network); 2 Jun 2004 23:20:53 -0000
Received: from unknown (HELO c60.cesmail.net) (192.168.1.105)
  by blade1.cesmail.net with SMTP; 2 Jun 2004 23:20:53 -0000
Received: from mailgate.cesmail.net (216.154.195.36)
  by c60.cesmail.net with SMTP; 02 Jun 2004 19:20:52 -0400
X-Ironport-AV: i="3.81R,93,1083556800";
  d="scan'217,208"; a="69470341:sNHT30062640"
Received: (qmail 21780 invoked from network); 2 Jun 2004 23:20:52 -0000
Received: from unknown (HELO mailgate.cesmail.net) (192.168.1.101)
  by mailgate.cesmail.net with SMTP; 2 Jun 2004 23:20:52 -0000
Received: from mail.cix.co.uk [212.241.168.136]
by mailgate.cesmail.net with POP3 (fetchmail-6.2.1)
for tifferg@spamcop.net (single-drop); Wed, 02 Jun 2004 19:20:52
-0400 (EDT)
Received: from stammstaufen.de (pool-68-160-126-158.nwrk.east.verizon.net
[68.160.126.158])
by mta02.mx.cix.co.uk (8.11.3/CIX/8.11.3) with SMTP id i52N7W630465
for <chris@gilliard.compulink.co.uk>; Thu, 3 Jun 2004 00:07:32 +0100
X-Envelope-From: c_hmoreno_wc@standitalia.it
Message-ID: <65f201c448f6$5008baec$888d2e31@stammstaufen.de>
From: "Craig H. Moreno" <c_hmoreno_wc@standitalia.it>
To: chris@gilliard.compulink.co.uk
Subject: ro.ckhard sti,ffys in mins
Date: Wed, 02 Jun 2004 23:10:54 +0000
MIME-Version: 1.0
Content-Type: text/html;
charset="us-ascii"
Content-Transfer-Encoding: 8bit
X-UIDL: 11886.1086217654.1242130molybdenum.bm
X-Spam-Checker-Version: SpamAssassin 2.63 (2004-01-11) on blade1
X-Spam-Level: *
X-Spam-Status: hits=1.8 tests=HTML_20_30,HTML_MESSAGE,J_CHICKENPOX_25,
J_CHICKENPOX_34,MIME_HTML_ONLY version=2.63
X-SpamCop-Checked: 192.168.1.105 216.154.195.36 192.168.1.101
212.241.168.136 68.160.126.158

(... HTML message clipped)

SMTP Info End ======================================

Generated by SpamX Version [SIZE=7]1.2.7
http://www.hendricom.com



Reading the headers myself, it appears to me that the originator's IP address is: 68.160.126.158

which ARIN reports as:
QUOTE
pool-68-160-126-158.nwrk.east.verizon.net
Host unreachable

68.160.0.0 - 68.163.255.255

Verizon Internet Services
1880 Campus Commons Dr
Reston
VA
20191
United States

Verizon Internet Services
+1-703-295-4583
noc@gnilink.net

Abuse:
VIS Abuse
+1-703-295-4583
abuse@verizon.net

NSDC.BA-DSG.NET
GTEPH.BA-DSG.NET

VIS-68-160
Created: 2002-08-30
Updated: 2003-07-18
Source: whois.arin.net


I guess it is a 1.27 bug as 1.2.6 (as shown below) correctly identifies Verizon as the culprit's home

QUOTE
ABUSE@VERIZON.NET;

Email Abuse Complaint
Here is the SMTP information.

SMTP Info Start ====================================

Return-Path: <c_hmoreno_wc@standitalia.it>
Delivered-To: spamcop-net-tifferg@spamcop.net
Received: (qmail 27876 invoked from network); 2 Jun 2004 23:20:53 -0000
Received: from unknown (HELO c60.cesmail.net) (192.168.1.105)
  by blade1.cesmail.net with SMTP; 2 Jun 2004 23:20:53 -0000
Received: from mailgate.cesmail.net (216.154.195.36)
  by c60.cesmail.net with SMTP; 02 Jun 2004 19:20:52 -0400
X-Ironport-AV: i="3.81R,93,1083556800";
  d="scan'217,208"; a="69470341:sNHT30062640"
Received: (qmail 21780 invoked from network); 2 Jun 2004 23:20:52 -0000
Received: from unknown (HELO mailgate.cesmail.net) (192.168.1.101)
  by mailgate.cesmail.net with SMTP; 2 Jun 2004 23:20:52 -0000
Received: from mail.cix.co.uk [212.241.168.136]
by mailgate.cesmail.net with POP3 (fetchmail-6.2.1)
for tifferg@spamcop.net (single-drop); Wed, 02 Jun 2004 19:20:52 -0400 (EDT)
Received: from stammstaufen.de (pool-68-160-126-158.nwrk.east.verizon.net [68.160.126.158])
by mta02.mx.cix.co.uk (8.11.3/CIX/8.11.3) with SMTP id i52N7W630465
for <chris@gilliard.compulink.co.uk>; Thu, 3 Jun 2004 00:07:32 +0100
X-Envelope-From: c_hmoreno_wc@standitalia.it
Message-ID: <65f201c448f6$5008baec$888d2e31@stammstaufen.de>
From: "Craig H. Moreno" <c_hmoreno_wc@standitalia.it>
To: chris@gilliard.compulink.co.uk
Subject: ro.ckhard sti,ffys in mins
Date: Wed, 02 Jun 2004 23:10:54 +0000
MIME-Version: 1.0
Content-Type: text/html;
charset="us-ascii"
Content-Transfer-Encoding: 8bit
X-UIDL: 11886.1086217654.1242130molybdenum.bm
X-Spam-Checker-Version: SpamAssassin 2.63 (2004-01-11) on blade1
X-Spam-Level: *
X-Spam-Status: hits=1.8 tests=HTML_20_30,HTML_MESSAGE,J_CHICKENPOX_25,
J_CHICKENPOX_34,MIME_HTML_ONLY version=2.63
X-SpamCop-Checked: 192.168.1.105 216.154.195.36 192.168.1.101 212.241.168.136 68.160.126.158

SMTP Info End ======================================

Generated by SpamX II Version 1.2.6
http://www.hendricom.com

Jeff Hendrickson
It is Verizon. I'm coming down the home stretch on the resolution for this for version 1.2.7.

I'll post a message on the board when it's ready for testing.

Thanks!
Tifferg
QUOTE (Jeff Hendrickson @ Jun 3 2004, 12:49 AM)
It is Verizon. 

I'm coming down the home stretch on the resolution for this for version 1.2.7.

Thanks Jeff. Guess it's a bit late to volunteer as a tester ;-) but I seem to have snuck in the back door <grin>
Jeff Hendrickson
It's not too late at all my friend, love to have your input!
Bazz
(Trying to keep the number of topis down a bit)..

This one:
QUOTE
Microsoft Mail Internet Headers Version 2.0
Received: from dup-200-64-60-218.prodigy.net.mx ([200.64.60.218]) by Lando.sdgworld.net with Microsoft SMTPSVC(5.0.2195.6713);
  Wed, 9 Jun 2004 18:16:08 +0100
Received: from J701 (yc62.32.32.217.dcss0.vms.CCAXPFBFDAMFT@everett.net [129.36.18.248])
by mail949.fgl.easynet.net (55.1.590g00/22.278.032) with SMTP id qyf2C901DFgfd31;
Mon, 07 Jun 2004 00:15:28 +0300
Message-Id: <53304407953.89.42@rexfi-ah200.localhost>
From: "Doug Hutchinson" <CCAXPFBFDAMFT@everett.net>
To: b.freeman@sdgworld.net
References: <ciceronian144-XJ87USlOmZ975G8t06@CCAXPFBFDAMFT@everett.net>
Subject: Heart and soul
Date: Sun, 06 Jun 2004 18:16:28 -0300
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="--2310928582128461723"
Return-Path: CCAXPFBFDAMFT@everett.net
X-OriginalArrivalTime: 09 Jun 2004 17:16:14.0578 (UTC) FILETIME=[77F9B520:01C44E45]

----2310928582128461723
Content-Type: text/plain;
charset="iso-9162-2"
Content-Transfer-Encoding: 7Bit


Picks up 62.32.32.217 which is forged, instead of 129.36.18.248 which is the actual posting address.

BAzz
Jeff Hendrickson
Hi BaZz...

I ran this here, and picked up the UNINET.NET.MX abuse address correctly.

It looks like one of two things happened. Either this first IP address crapped out on your 'do not send' list, or the answer timed out on the first IP address.
Bazz
I ran it seveal times...

I think I'll empty my DNS list and just keep th minimum in there..

BAzz
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2012 Invision Power Services, Inc.