Ik ontvang steeds meer spam vanuit het
179 netblock (CIDR 179.0.0.0/8 )
- IANA reserved
http://mail-abuse.org/cgi-bin/lookup?179.79.169.80
geeft duidelijk aan:
http://mail-abuse.org/cgi-bin/show_listing.cgi?392537
"This network address is reserved by the Internet Assigned Numbers
Authority (IANA). No Internet traffic should originate from this
address. Any packets with this source address can be assumed to
be forged."
Lijkt duidelijk. Vervalste origin IP in de Header.
Volgens ARIN
http://netgeo.caida.org/perl/netgeo....=179.79.169.80
is dit adres nochtans in gebruik (door?):
TARGET: 179.79.169.80
NAME: NET179
NUMBER: 179.0.0.0 - 179.255.255.255
CITY: CHANTILLY
STATE: VIRGINIA
COUNTRY: US
LAST_UPDATED: 01-May-1993
NIC: ARIN
LOOKUP_TYPE: Block Allocation
Probleem blijft de SPAM routing:
de 1e received van deze Fake IP (?) Spam
lijken vaak Belgacom/Skynet ADSL klanten,
waarna de Spam mijn Telenet/pandora account bereikt.
---routing vd SPAM:
Received: from unknown (HELO karpos.telenet-ops.be) ([195.130.132.60])
(envelope-sender <gc3quzldw@norikomail.com>)
by angelia.telenet-ops.be (qmail-ldap-1.03) with SMTP
for <-----@pandora.be>; 14 Nov 2003 06:15:48 -0000
Received: from 127.0.0.1 (localhost [127.0.0.1])
by karpos.telenet-ops.be (Postfix) with SMTP
id 69FFE4005A; Fri, 14 Nov 2003 07:15:34 +0100 (MET)
Received: from 52-135.240.81.adsl.skynet.be (52-135.240.81.adsl.skynet.be
[81.240.135.52])
by iris.telenet-ops.be (Postfix) with SMTP
id C5F1338438; Fri, 14 Nov 2003 07:14:33 +0100 (MET)
Received: from [179.79.169.80] <<=== *onmogelijk?
by 52-135.240.81.adsl.skynet.be id <0971521-69679>;
Fri, 14 Nov 2003 12:09:44 +0600
Message-ID: <881$9gh888-$8$4-a-0@9aqqr1>
From: "Matthew Starks" <gc3quzldw@norikomail.com>
Reply-To: "Matthew Starks" <gc3quzldw@norikomail.com>
To: -----@pandora.be
Subject: Looking for ----
---
Mijn junkmail filter meldde "origin blacklisted by Spamcop"
Functioneert de ADSL Skynet.be klant hier als een mail relay
voor spam originating van een faked IP?

Likes:

Quote
)