Re: Mail spoofing

Bruce Carter (bcarter@mentor.idbsu.edu)
Tue, 9 Apr 1996 11:54:27 EDT

At 11:48 PM 4/8/96, Alice Smithson wrote:
>My question is how would they be caught? If a student knows how to do
>this, won't they also know that they probably will not get caught? Isn't
>that asking them to break the rules? I mean if I drive over the speed
>limit, I know that a percentage of the time I will get caught. Is this
>true in this situation?

It is sometimes possible to backtrack this activity using the full headers
associated with the SMTP traffic. That will at least get you to the
machine or port that originated the message. With server addressing that's
pretty much useless unless you're keeping some pretty detailed logs, but
with static addressing it can be valuable information. If you have static
addresses and sign-in logs, you may be able to catch your spoofer.

On the other hand, there's always the old looking over the shoulder
method... *heh*.

--
Bruce Carter, Instructional Software Designer     (208)385-1851@voice
Boise State University, Boise, ID  83725          (208)385-1856@fax
http://mentor.idbsu.edu/BruceCarter/home.html     bcarter@mentor.idbsu.edu