View Single Post
Old 08-23-2003, 06:39 PM   #7 (permalink)
Nizzle
God-Hating Liberal
 
Location: Silicon Valley, CA
ARIN whois information, traceroutes and the like are not going to do you any good. Even if you were, hypothetically, able to track it to someone's home address, what would you do? Go beat them up?

The proper thing to do is to block the IP of the SMTP server with a firewall and either wait it out, or send mail to abuse@twtelecom.net to speed it up.

To clear a bit of misinformation about SoBig: It spoofs the "From:" header in the email. The header of an email is supplied by the sender and can be set to anything you want it to be, provided the mail client gives you the option.

SoBig is unable to spoof an IP address.

Spoofing the src header of a TCP packet is possible, but the handshake-style negotiation would make it impossible to do this over the Internet. The spoofer would need access to your LAN and some sophisticated tools.
__________________
Nizzle
Nizzle is offline  
 

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76