About RIPE | Contact  | Search | Sitemap    
Homepage RIPE  
RIPE Community Mail Archives
search  
     
RIPE Navigation Ends
About RIPE Maillists
Maillists Archive
Global Lists
Non Active Lists
RIPE NCC Navigation Ends
Next Section
<<< Chronological >>> Author Index    Subject Index <<< Threads >>>

From Address Forged

  • To:
  • From: Daniel Karrenberg < >
  • Date: Tue, 03 Nov 1998 21:30:14 +0100
  • Cc: RIPE Local Internet Registries WG < >

To be perfectly clear: 'forging' mail headers to get around mail-from
authentication is not accepted behaviour. 

To quote from ripe-120: "Each RIPE database object has an optional
attribute called mnt-by (maintained by).  The value of the mnt-by
attribute is a reference to a mntner object in the database which
describes those authorised to make changes to the object."

So forging the mail header must be seen as a deliberate attempt to
modify data one is not authorised to modify and defeating a protection
scheme (however weak) to do so.  This is a crime in most places
nowadays.  If it is true and we can identify the person who did this
beyond doubt, they will owe all "victims" more than an apology. 

This is the first I hear of mail-from protected objects being modified
too.  I have been on travel for more than a week now and was not at the
NCC when this happened.  So my knowledge about the facts is sketchier
than I'd like.  If this is true I would assume malicious intent on the
part of the the person concerned.  I have asked the database staff to
look into this a bit further. 

More tomorrow (European time)

Daniel



  > Wilhelm Buehler hostmaster@localhost writes:
  > 
  > But you should not use the auth: MAIL-FROM !!!
  > 
  > We were happy with the MAIL-FROM for years now ... but our "friend" 
  > from rain.fr knows to fake message-id and from-line.
  > 
  > | >   From:    Trevor McBryan hostmaster@localhost
  > | >   Cc:      hostmaster@localhost         
  > | >   Subject: longack 
  > | >   Date:    Wed, 28 Oct 1998 12:34:27 +0000
  > | >   Msg-Id:  <36370F53.30E4F99F@localhost
  > |
  > | [...]  
  > |
  > | Delete OK: [person] MW1699-RIPE (Martin Weber)




  • Post To The List:
<<< Chronological >>> Author    Subject <<< Threads >>>
 

Next Section
     About RIPE | Site Map | LIR Portal | About the RIPE NCC | Contact | © RIPE Community. All rights reserved.
RIPE.NET Homepage LIR Portal RIPE Community