> Can someone explain to me in details how SPAM happens???
> How do the spammer hijack?
It is very easy. They have an E-mail client that is designed to send to lots and lots
of users (they could use Eudora or Outlook or whatever, but the software they use
makes it easier to send to lots of users). They put your SMTP server address in their
E-mail client, just like a regular user does. Then they send the messages, just like
a regular user does.
"Hijack" isn't really an appropriate term to describe HOW the spammers work. They
don't need to do anything illegal (besides using your SMTP server without your
permission), or anything unusual (as a hacker might).
> Do they use password cracking software,
No need to. If your system is not set up to deny "relaying" (people that don't have
an account on your system sending E-mail to other people that don't have an account on
your system), they don't need a password.
With SMTP, the E-mail client says "Hi, I'm [EMAIL PROTECTED] I want to send an E-mail
to [EMAIL PROTECTED]". The E-mail client doesn't have to prove that he
really is [EMAIL PROTECTED]
> or do they just spoof the header? If they spoof the header, how
> do they use it to spam?
Although spammers usually spoof the headers, they rarely need to. The only reason
they would have to is if you set up your E-mail server to only allow E-mail from your
domain(s), based on who the user claimed to be. In that case, they could "spoof" the
headers and say they were "[EMAIL PROTECTED]". Spoofing E-mail address headers
isn't difficult; you just tell your E-mail client that you are "[EMAIL PROTECTED]".
Your E-mail client doesn't know or care who you really are.
-Scott
Please visit http://www.ipswitch.com/support/mailing-lists.html
to be removed from this list.
An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/