LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 02-23-2012, 08:21 AM   #1
mmem700
LQ Newbie
 
Registered: Jan 2012
Posts: 27

Rep: Reputation: Disabled
How To Spoof FROM Header


I am testing an email server and I want to verify that it protects users from spoofing the FROM header.

Is there any software in Windows or Linux that makes spoofing the FROM header easy?

Please don't recommend Telnet because it's too messy to work with SASL authentication for this test (unless you have an easy way to do that).

Thanks.
 
Old 02-23-2012, 01:20 PM   #2
ButterflyMelissa
Senior Member
 
Registered: Nov 2007
Location: Somewhere on my hard drive...
Distribution: Manjaro
Posts: 2,766
Blog Entries: 23

Rep: Reputation: 411Reputation: 411Reputation: 411Reputation: 411Reputation: 411
Well, it may not be that hard, and I may be able to provide with some background...

This is the actual source of a mail:

Quote:
Return-path: <user@example.com>
Received: from mac.com ([10.13.11.252])
by ms031.mac.com (Sun Java System Messaging Server 6.2-8.04 (built Feb 28
2007)) with ESMTP id <0JMI007ZN7PETGC0@ms031.mac.com> for user@example.com; Thu,
09 Aug 2007 04:24:50 -0700 (PDT)
Received: from mail.dsis.net (mail.dsis.net [70.183.59.5])
by mac.com (Xserve/smtpin22/MantshX 4.0) with ESMTP id l79BOnNS000101
for <user@example.com>; Thu, 09 Aug 2007 04:24:49 -0700 (PDT)
Received: from [192.168.2.77] (70.183.59.6) by mail.dsis.net with ESMTP
(EIMS X 3.3.2) for <user@example.com>; Thu, 09 Aug 2007 04:24:49 -0700
Date: Thu, 09 Aug 2007 04:24:57 -0700
From: Frank Sender <sender@example.com>
Subject: Test
To: Joe User <user@example.com>
Message-id: <61086DBD-252B-46D2-A54C-263FE5E02B41@example.com>
MIME-version: 1.0 (Apple Message framework v752.2)
X-Mailer: Apple Mail (2.752.2)
Content-type: text/plain; charset=US-ASCII; format=flowed
Content-transfer-encoding: 7bit
I marked the points of interest for you. Differences in these fields could mean a spoofed mail...

I suggest a grep tru the source text to find out where the differences are...

Just some loose thoughts...I had a sunday's worth of entertainment with this too, once...
Oh, and by the way, this method will of course not be able to detect/filter messages from a hacked mail account, there the returnpathe and from fiels should be the same...

Good luck

Thor
(maybe a better example is called for)

Last edited by ButterflyMelissa; 02-23-2012 at 01:26 PM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Want to add data in the header field of tcp/ip header Maitrikkshah Linux - Networking 1 08-06-2011 06:07 AM
How to check missing header files included from another header file adisan82 Linux - Software 1 01-28-2011 03:57 AM
Spoof HTTP header to particular program xkero Linux - Networking 2 01-26-2008 06:49 AM
How to spoof the ip ! Anafura Linux - General 2 01-02-2005 06:14 PM
How to spoof our ip?? zLinuxz Linux - Networking 2 04-19-2002 11:00 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 06:45 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration