LWN.net Logo

email harvesting

email harvesting

Posted Sep 18, 2003 17:25 UTC (Thu) by pflugstad (subscriber, #224)
Parent article: Whose Internet is it?

The thing about the idiot SMTP server that they're running on the site finder, is that it does take the first couple of lines, then after the 3rd one or so, it spits back and error and hangs up.

Since the first couple of lines typically includes the From: line, this means that Verisign could easily be capturing these From: lines (presumedly real, valid email addresses) and may the From: and To: (which in this case is probably a mistyped email address) relationship as well.

So, what are they going to do with this information? Hmmm, can anyone else say SPAM?? Think how much SPAMMERs would pay for a list of *verified* address (the From: line).


(Log in to post comments)

email harvesting

Posted Sep 22, 2003 20:31 UTC (Mon) by TheManInBlack (guest, #8154) [Link]

I'm testing this.... and I encourage others to do so as well.

I created a bogus email account on my mail server. Then sent some emails to a mistyped domain that resolved to the verisign 64.95.110.11

I'm also trying telneting in and putting my BS address in a standard MAIL FROM command.

This new address has never been used and doesn't exist on any web page. I administer this mail server; It's very small, not like an ISPs server so dictionary attacks are unlikely.

We'll see if my honeypot gets any hits.

- MIB

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds