OMG!!! I'm being spammed by an idiot now. While it does fall under the "forged header" category (which means I can sue for $$$), he's not selling anything (which means I can't sue, I think).
Anyways, following is the header and body of the message after it passed through SpamAssassin. The message purported to be from rickisok@bahn.de but actually originated from a originated from an IP address belonging to the Department of Social Security of UK!!! (Methinks that someone is testing a Jeem or SoBig worm-compromised system within the GB.)
For those of you new to reading message headers, you read the "Received" lines from the bottom up (for chronological order). I can vouch for anything generated by cox.net as being legit.
| Return-Path: Received: from pop.cox.east by localhost with POP3 (fetchmail-6.2.1) for joat@localhost (single-drop); Wed, 23 Jul 2003 06:30:18 -0400 (EDT) Received: from host-148-244-152-186.block.alestra.net.mx ([200.76.178.243]) by lakemtai04.cox.net (InterMail vM.5.01.04.05 201-253-122-122-105-20011231) with SMTP id ; Wed, 23 Jul 2003 06:24:26 -0400 Received: from vi3m.4fyzhbh.net [51.41.95.3] by host-148-244-152-186.block.alestra.net.mx id for ; Wed, 23 Jul 2003 15:09:43 +0200 Message-ID: From: rickisok@bahn.de To: xxxx.xxxx@cox.net, krarge@cox.net, krastonscott@cox.net, kratten@cox.net, kraut1-9@cox.net, krawietz@cox.net, kraynekg@cox.net Subject: *****SPAM***** Need Dimensional Warp Generator ahd Date: Wed, 23 Jul 03 15:09:43 GMT X-Priority: 3 X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook Express 5.00.2919.6700 MIME-Version: 1.0 Content-Type: text/plain X-Spam-Status: Yes, hits=4.0 required=4.0 tests=MISSING_MIMEOLE,NO_REAL_NAME,SPAM_PHRASE_02_03, SUPERLONG_LINE,SUSPICIOUS_RECIPS,USER_AGENT_OE, VERY_SUSP_RECIPS version=2.44 X-Spam-Flag: YES X-Spam-Level: **** X-Spam-Checker-Version: SpamAssassin 2.44 (1.115.2.24-2003-01-30-exp) X-Spam-Prev-Content-Type: multipart/alternative; boundary="E.3.EAD.3C" X-Evolution-Source: imap://joat@127.0.0.1/
SPAM:
|
|
No comments:
Post a Comment