Detecting improper Received: path

Hugo van der Kooij hvdkooij at vanderkooij.org
Sat Mar 22 12:13:20 GMT 2008


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi,

Is there code to track the Received: headers and see if a ADSL user has
used his/her smarthost?

I see quite a bit of relaying going on like shown below:

	Received: from lists-outbound.sourceforge.net
(lists-outbound.sourceforge.net [66.35.250.225])
~     by balin.waakhond.net (Postfix) with ESMTP id 564F417E8F92
~     for <hvdkooij at vanderkooij.org>; Sat, 22 Mar 2008 04:06:55 +0100 (CET)
Received: from sc8-sf-list1-new.sourceforge.net
(sc8-sf-list1-new-b.sourceforge.net [10.3.1.93])
~     by sc8-sf-spam2.sourceforge.net (Postfix) with ESMTP
~     id 597FE127B0; Fri, 21 Mar 2008 19:06:53 -0800 (PST)
Received: from sc8-sf-mx2-b.sourceforge.net ([10.3.1.92]
~     helo=mail.sourceforge.net)
~     by sc8-sf-list1-new.sourceforge.net with esmtp (Exim 4.43)
~     id 1Jcu4J-0003zq-Si
~     for ddj-users at lists.sourceforge.net; Fri, 21 Mar 2008 20:06:51 -0700
Received: from [59.92.245.155] (helo=[59.92.245.155])
~     by mail.sourceforge.net with esmtp (Exim 4.44) id 1Jcu4H-0006ue-Ox
~     for ddj-users at lists.sourceforge.net; Fri, 21 Mar 2008 20:06:51 -0700
Message-ID: <01c88bf7$deba6680$9bf55c3b at whitneyin8>
From: "Antonio Bowden" <whitneyin8 at anazamani.com>
To: <ddj-users at lists.sourceforge.net>
Date: Sat, 22 Mar 2008 08:36:49 +0530
MIME-Version: 1.0
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2800.1506
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1506
X-Spam: Not detected
X-Spam-Score: 2.1 (++)
X-Spam-Report: Spam Filtering performed by sourceforge.net.
~     See http://spamassassin.org/tag/ for more details.
~     Report problems to
~     http://sf.net/tracker/?func=add&group_id=1&atid=200001
~     0.1 RCVD_IN_SORBS_DUL RBL: SORBS: sent directly from dynamic IP
address
~     [59.92.245.155 listed in dnsbl.sorbs.net]
~     2.0 RCVD_IN_DSBL RBL: Received via a relay in list.dsbl.org
~     [<http://dsbl.org/listing?59.92.245.155>]
Subject: [Ddj-users] Office Enterprise 2007 ready to download
X-BeenThere: ddj-users at lists.sourceforge.net
X-Mailman-Version: 2.1.8
Precedence: list
List-Id: <ddj-users.lists.sourceforge.net>
List-Unsubscribe: <https://lists.sourceforge.net/lists/listinfo/ddj-users>,
~     <mailto:ddj-users-request at lists.sourceforge.net?subject=unsubscribe>
List-Archive:
<http://sourceforge.net/mailarchive/forum.php?forum_name=ddj-users>
List-Post: <mailto:ddj-users at lists.sourceforge.net>
List-Help: <mailto:ddj-users-request at lists.sourceforge.net?subject=help>
List-Subscribe: <https://lists.sourceforge.net/lists/listinfo/ddj-users>,
~     <mailto:ddj-users-request at lists.sourceforge.net?subject=subscribe>
Content-Type: text/plain; charset="windows-1252"
Content-Transfer-Encoding: quoted-printable
Sender: ddj-users-bounces at lists.sourceforge.net
Errors-To: ddj-users-bounces at lists.sourceforge.net


Granted the DDJ mailinglist has about a 100% spam rate so I could just
unsubscribe and be done with it but I have some faint hopes Mike will
actually continue to support DDJ and GRIP.

But in this case it is clear that this message should propably have been
stopped by Sourceforge in the first place.

The Barracuda can do tricks like this lately by defining hosts as
trusted relays. It will then check the Received headers to see who
connected to the trusted relay. If that host would not have been allowed
to connect to the Barracuda then the Barracuda will kill the message.

While primeraly intended for your backup MX servers it also works for
mailinglist servers that you get email from.

Is there a way to do something similar in MailScanner?

Hugo.

- --
hvdkooij at vanderkooij.org               http://hugo.vanderkooij.org/
PGP/GPG? Use: http://hugo.vanderkooij.org/0x58F19981.asc

	A: Yes.
	>Q: Are you sure?
	>>A: Because it reverses the logical flow of conversation.
	>>>Q: Why is top posting frowned upon?

Bored? Click on http://spamornot.org/ and rate those images.

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (GNU/Linux)

iD8DBQFH5PfdBvzDRVjxmYERArw7AJ0U2Int2WQAvXeum1K4Npu68fuO1gCeK5Zs
zyWDqYXAg8StM19cBWsWOCQ=
=jrCw
-----END PGP SIGNATURE-----


More information about the MailScanner mailing list