> Can someone explain to me in details how SPAM happens???
> How do the spammer hijack?

It is very easy.  They have an E-mail client that is designed to send to lots and lots 
of users (they could use Eudora or Outlook or whatever, but the software they use 
makes it easier to send to lots of users).  They put your SMTP server address in their 
E-mail client, just like a regular user does.  Then they send the messages, just like 
a regular user does.

"Hijack" isn't really an appropriate term to describe HOW the spammers work.  They 
don't need to do anything illegal (besides using your SMTP server without your 
permission), or anything unusual (as a hacker might).

> Do they use password cracking software, 

No need to.  If your system is not set up to deny "relaying" (people that don't have 
an account on your system sending E-mail to other people that don't have an account on 
your system), they don't need a password.

With SMTP, the E-mail client says "Hi, I'm [EMAIL PROTECTED]  I want to send an E-mail 
to [EMAIL PROTECTED]".  The E-mail client doesn't have to prove that he 
really is [EMAIL PROTECTED]

> or do they just spoof the header? If they spoof the header, how 
> do they use it to spam?

Although spammers usually spoof the headers, they rarely need to.  The only reason 
they would have to is if you set up your E-mail server to only allow E-mail from your 
domain(s), based on who the user claimed to be.  In that case, they could "spoof" the 
headers and say they were "[EMAIL PROTECTED]".  Spoofing E-mail address headers 
isn't difficult; you just tell your E-mail client that you are "[EMAIL PROTECTED]".  
Your E-mail client doesn't know or care who you really are.
                                 -Scott

Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/

Reply via email to