>Hey guys, I got some weird emails on Friday night / early Saturday morning.
>A few hours before I had my T1 go down, could it be related?
maybe, maybe not
>The body of the emails say:
>
>6 from www.InfoGiant.com: Unknown host
>
>The headers say:
>
>Received: from thunderstone.com [208.51.0.81] by mail.infodish.com with
>ESMTP
> (SMTPD32-6.05) id A6121890388; Sat, 24 Mar 2001 03:33:38 -0800
# dig -x 208.51.0.81
; <<>> DiG 8.3 <<>> -x
;; res options: init recurs defnam dnsrch
;; got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 4
;; flags: qr aa rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 2, ADDITIONAL: 2
;; QUERY SECTION:
;; 81.0.51.208.in-addr.arpa, type = ANY, class = IN
;; ANSWER SECTION:
81.0.51.208.in-addr.arpa. 4H IN PTR thunder.thunderstone.com.
>Received: from [208.51.1.102] (helo=m2.master.com)
> by thunderstone.com with esmtp (Exim 2.10 #1)
> id 14glCZ-0002oO-00
> for [EMAIL PROTECTED]; Sat, 24 Mar 2001 05:23:19 -0500
# dig -x 208.51.0.102
; <<>> DiG 8.3 <<>> -x
;; res options: init recurs defnam dnsrch
;; got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 4
;; flags: qr aa rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 2, ADDITIONAL: 2
;; QUERY SECTION:
;; 102.0.51.208.in-addr.arpa, type = ANY, class = IN
;; ANSWER SECTION:
102.0.51.208.in-addr.arpa. 4H IN PTR float.thunderstone.com.
>They were sent from [EMAIL PROTECTED]
prove it
>but no one has access to that account but me.
Ever heard of mail header spoofing? You can't trust any mail headers.
Len
http://MenAndMice.com/DNS-training : In Austin, TX; SFO, CA; Paris,
FR
http://BIND8NT.MEIway.com : ISC BIND 8.2.3 "NT3" for NT4 & W2K
http://IMGate.MEIway.com : Build free, hi-perf, anti-abuse mail gateways
Please visit http://www.ipswitch.com/support/mailing-lists.html
to be removed from this list.
An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/