>I don't buy this. If you could compromise a relay using IP spoofing, a
>much more transparent method than username spoofing (since the latter,
>alone,  leaves  you vulnerable to RBL checks of your IP), why wouldn't
>you  use  that  first?

how do you know they don't, but fail due to anti-spoofing at the border 
router and so fall back to non-spoofed relay attempt?

tcp/ip spoofing is probably very rare anyway.  There are 100's of 1000's of 
open relays and proxies, and friendly network operattors,  available 
without spoofing.

Len


____________________________________________________________________
www.menandmice.com/DNS-training : DNS Training
BIND8NT.MEIway.com: Secure config ; DNS and mail interactions
IMGate.MEIway.com : Free, proven config for anti-mail-abuse gateways


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to