banner

[Rule] Rules  [Home] Main Forum  [Portal] Portal  
[Members] Member Listing  [Statistics] Statistics  [Search] Search  [Reading Room] Reading Room 
[Register] Register  
[Login] Loginhttp  | https  ]
 
Forum Index Thảo luận mạng và thiết bị mạng [Thảo luận] Tìm hiểu các IP trong một mail header  XML
  [Question]   [Thảo luận] Tìm hiểu các IP trong một mail header 17/01/2008 06:21:42 (+0700) | #1 | 110632
[Avatar]
quanta
Moderator

Joined: 28/07/2006 14:44:21
Messages: 7265
Location: $ locate `whoami`
Offline
[Profile] [PM]
Tôi đã đọc topic này và bài trả lời của anh conmale. Nay xin đưa ra một vài cái mail header để mọi người thảo luận thêm về từng địa chỉ IP trong mỗi trường hợp.

1.

Delivered-To: ToAddress@gmail.com
Received: by 10.141.164.3 with SMTP id r3cs302437rvo;
Tue, 15 Jan 2008 21:52:20 -0800 (PST)
Received: by 10.101.68.19 with SMTP id v19mr872595ank.4.1200462739628;
Tue, 15 Jan 2008 21:52:19 -0800 (PST)
Return-Path: <FromAddress@yahoo.com>
Received: from web56306.mail.re3.yahoo.com (web56306.mail.re3.yahoo.com [216.252.110.230])
by mx.google.com with SMTP id r28si605103ele.0.2008.01.15.21.52.18;
Tue, 15 Jan 2008 21:52:19 -0800 (PST)
Received-SPF: pass (google.com: domain of FromAddress@yahoo.com designates 216.252.110.230 as permitted sender) client-ip=216.252.110.230;
DomainKey-Status: good (test mode)
Authentication-Results: mx.google.com; spf=pass (google.com: domain of FromAddress@yahoo.com designates 216.252.110.230 as permitted sender) smtp.mail=FromAddress@yahoo.com; domainkeys=pass (test mode) header.From=FromAddress@yahoo.com
Received: (qmail 87465 invoked by uid 60001); 16 Jan 2008 05:52:18 -0000
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws;
s=s1024; d=yahoo.com;
h=X-YMail-OSG:Receivedsmilieate:From:Subject:To:MIME-Version:Content-Type:Content-Transfer-Encoding:Message-ID;
b=R3jhqZLUj6bbBt+v5qKaZMMawGorruHGldhlQux+8Dy/nTRLHfsaHA/mG8nG0PCfYn98yf0Trt5uErGVIii2EYuX8Ohvy+5adSG5NtAQvv1BEt2wcEvQ14St4QG/BX0OJKyqVXFk1jzLNbikXMH6SkSbOqXFNPb6yi+393Y/X28=;
X-YMail-OSG: oXhBBE8VM1kWeZRl3i9GXs.KhS1lYhRhfNKvJyeuTwyISCVVRauFFhwzl2yfgYlMCim4_Y5lXXWQdAKC57bXPgdS_O.KBECx1wVlYGLdkeHfTNht5d.TW3edhpjXQmFs6wL2RDoLcdluipOTg4svQ0kTtQ--
Received: from [220.231.124.6] by web56306.mail.re3.yahoo.com via HTTP; Tue, 15 Jan 2008 21:52:18 PST
Date: Tue, 15 Jan 2008 21:52:18 -0800 (PST)
 


2.

Delivered-To: ToAddress
Received: by 10.141.164.3 with SMTP id r3cs299973rvo;
Tue, 15 Jan 2008 20:34:57 -0800 (PST)
Received: by 10.114.110.1 with SMTP id i1mr363652wac.112.1200458097181;
Tue, 15 Jan 2008 20:34:57 -0800 (PST)
Return-Path: <FromAddress>
Received: from wa-out-1112.google.com (wa-out-1112.google.com [209.85.146.182])
by mx.google.com with ESMTP id j31si588588waf.38.2008.01.15.20.34.56;
Tue, 15 Jan 2008 20:34:57 -0800 (PST)
Received-SPF: neutral (google.com: 209.85.146.182 is neither permitted nor denied by best guess record for domain of ToAddress) client-ip=209.85.146.182;
Authentication-Results: mx.google.com; spf=neutral (google.com: 209.85.146.182 is neither permitted nor denied by best guess record for domain of FromAddress) smtp.mail=FromAddress
Received: by wa-out-1112.google.com with SMTP id l24so201692waf.22
for <ToAddress>; Tue, 15 Jan 2008 20:34:56 -0800 (PST)
Received: by 10.114.130.1 with SMTP id c1mr387569wad.52.1200458095825;
Tue, 15 Jan 2008 20:34:55 -0800 (PST)
Received: by 10.115.46.2 with HTTP; Tue, 15 Jan 2008 20:34:55 -0800 (PST)
Message-ID: <5508fadc0801152034u6809aa53sa11714afec862b0d@mail.gmail.com>
Date: Wed, 16 Jan 2008 11:34:55 +0700
 


3.

Delivered-To: ToAddress
Received: by 10.78.37.12 with SMTP id k12cs211327huk;
Thu, 27 Dec 2007 17:06:50 -0800 (PST)
Received: by 10.78.21.7 with SMTP id 7mr10663551huu.5.1198804010214;
Thu, 27 Dec 2007 17:06:50 -0800 (PST)
Return-Path: <FromAddress>
Received: from hu-out-0506.google.com (hu-out-0506.google.com [72.14.214.230])
by mx.google.com with ESMTP id 32si3807504hui.1.2007.12.27.17.06.49;
Thu, 27 Dec 2007 17:06:50 -0800 (PST)
Received-SPF: pass (google.com: domain of FromAddress designates 72.14.214.230 as permitted sender) client-ip=72.14.214.230;
Authentication-Results: mx.google.com; spf=pass (google.com: domain of FromAddress designates 72.14.214.230 as permitted sender) smtp.mail=FromAddress; dkim=pass (test mode) header.i=@gmail.com
Received: by hu-out-0506.google.com with SMTP id 28so26822hub.8
for <ToAddress>; Thu, 27 Dec 2007 17:06:49 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=gmail.com; s=gamma;
h=domainkey-signature:received:received:message-id:date:from:user-agent:mime-version:to:subject:content-type:content-transfer-encoding;
bh=5+X5fTMWewS1a/NCLyv5/+IgqT18MbqH3N+kaVrtclc=;
b=Fe3fKox8BKYCvY76Cr3T0Cop9vfygeBqv+5mq5AIj6f30YMDBfzan+lyHCb8T+yuKnjyEQ3SH+0yWLj9tzBKB7zI2zls3KMYmROQ60J4BlUQnQcC9DCqBAB/E15wDqtO48xalR2DBfdp0nTyLGVjjfDCC8hB8G/XbZXPl/c0AZE=
DomainKey-Signature: a=rsa-sha1; c=nofws;
d=gmail.com; s=gamma;
h=message-id:date:from:user-agent:mime-version:to:subject:content-type:content-transfer-encoding;
b=s7uYW8DVsr3TQ/hiGL4BrpFkafdyCKq2jOtY7+pV5SzNVqs75IT5vC66euHbStkONlxeBzYOYvU5i6ikc0lXpFLbcL0+1JSkHQzmGyVV+EY5qE/EdNTAfgpDnSRYJ13VUh4hgscgRK0nRODiw/QU2MP9MlmVUXg4OO1mSPiH+rk=
Received: by 10.67.30.3 with SMTP id h3mr7673815ugj.35.1198804008717;
Thu, 27 Dec 2007 17:06:48 -0800 (PST)
Return-Path: <FromAddress>
Received: from ?192.168.77.87? ( [195.128.96.165])
by mx.google.com with ESMTPS id u6sm31261285uge.83.2007.12.27.17.06.46
(version=TLSv1/SSLv3 cipher=RC4-MD5);
Thu, 27 Dec 2007 17:06:47 -0800 (PST)
Message-ID: <47744C23.2000607@gmail.com>
Date: Fri, 28 Dec 2007 04:06:43 +0300
 
Let's build on a great foundation!
[Up] [Print Copy]
  [Question]   Re: [Thảo luận] Tìm hiểu các IP trong một mail header 01/06/2009 14:01:57 (+0700) | #2 | 182535
mR.Bi
Member

[Minus]    0    [Plus]
Joined: 22/03/2006 13:17:49
Messages: 812
Offline
[Profile] [PM] [WWW]
rfc822:
Field Receive và Return Path nằm trong vùng Trace Fields, thông tin này quan trọng nếu muốn dò tìm ra thủ phạm spam mail hoặc đơn giản chỉ là người gửi mail.
Receive field và Return Path field có nhiều giá trị, những giá trị này phụ thuộc vào bao nhiêu hops (Email system) mà email này đã đi qua và được xử lí từ phía người gửi đến người nhận.

Những IP anh tô màu ở trên là những computer đã xử lí cái email đó trước khi đến được người nhận.

All of my life I have lived by a code and the code is simple: "honour your parent, love your woman and defend your children"
[Up] [Print Copy]
  [Question]   Tìm hiểu các IP trong một mail header 03/06/2009 12:31:25 (+0700) | #3 | 182691
camazalraman
Member

[Minus]    0    [Plus]
Joined: 19/05/2004 01:57:32
Messages: 23
Offline
[Profile] [PM]
Header của một mail spam với From và To giống nhau, ví dụ abc@mycompany.com gửi cho chính abc@mycompany.com

Received: from mycompany.com ([x.x.x.x]) by mycompany.com with Microsoft SMTPSVC(6.0.3790.3959);
Wed, 6 May 2009 19:36:50 +0700
Received: from PC-BELSERS ([84.160.105.68]) by mycompany.com with Microsoft SMTPSVC(6.0.3790.3959);
Wed, 6 May 2009 19:36:49 +0700
X-Originating-IP: [02.5.920.238]
X-Originating-Email: [xxx@mycompany.com]
X-Sender: xx@mycompany.com">xxx@mycompany.com
Return-Path: xx@mycompany.com">xxx@mycompany.com
To: xx@mycompany.com">xxx@mycompany.com
Subject: RE: SALE 70% 0FF on Pfizer
From: VIAGRA ® Official Site <xxx@mycompany.com>
MIME-Version: 1.0
Importance: High
Content-Type: text/html; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
Message-ID: <01n3GCIFoPk00000a38@mycompany.com>
X-OriginalArrivalTime: 06 May 2009 12:36:49.0524 (UTC) FILETIME=[53797B40:01C9CE47]
Date: 6 May 2009 19:36:49 +0700 

[Up] [Print Copy]
[digg] [delicious] [google] [yahoo] [technorati] [reddit] [stumbleupon]
Go to: 
 Users currently in here 
1 Anonymous

Powered by JForum - Extended by HVAOnline
 hvaonline.net  |  hvaforum.net  |  hvazone.net  |  hvanews.net  |  vnhacker.org
1999 - 2013 © v2012|0504|218|