>Hey guys, I got some weird emails on Friday night / early Saturday morning.
>A few hours before I had my T1 go down, could it be related?

maybe, maybe not

>The body of the emails say:
>
>6 from www.InfoGiant.com: Unknown host
>
>The headers say:
>
>Received: from thunderstone.com [208.51.0.81] by mail.infodish.com with
>ESMTP
>   (SMTPD32-6.05) id A6121890388; Sat, 24 Mar 2001 03:33:38 -0800

# dig -x 208.51.0.81

; <<>> DiG 8.3 <<>> -x
;; res options: init recurs defnam dnsrch
;; got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 4
;; flags: qr aa rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 2, ADDITIONAL: 2
;; QUERY SECTION:
;;      81.0.51.208.in-addr.arpa, type = ANY, class = IN

;; ANSWER SECTION:
81.0.51.208.in-addr.arpa.  4H IN PTR  thunder.thunderstone.com.


>Received: from [208.51.1.102] (helo=m2.master.com)
>         by thunderstone.com with esmtp (Exim 2.10 #1)
>         id 14glCZ-0002oO-00
>         for [EMAIL PROTECTED]; Sat, 24 Mar 2001 05:23:19 -0500

# dig -x 208.51.0.102

; <<>> DiG 8.3 <<>> -x
;; res options: init recurs defnam dnsrch
;; got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 4
;; flags: qr aa rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 2, ADDITIONAL: 2
;; QUERY SECTION:
;;      102.0.51.208.in-addr.arpa, type = ANY, class = IN

;; ANSWER SECTION:
102.0.51.208.in-addr.arpa.  4H IN PTR  float.thunderstone.com.


>They were sent from [EMAIL PROTECTED]

prove it

>but no one has access to that account but me.

Ever heard of mail header spoofing?  You can't trust any mail headers.

Len




http://MenAndMice.com/DNS-training : In Austin, TX; SFO, CA; Paris, 
FR
http://BIND8NT.MEIway.com : ISC BIND 8.2.3 "NT3" for NT4 & W2K
http://IMGate.MEIway.com  : Build free, hi-perf, anti-abuse mail gateways


Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/

Reply via email to