Home Page    Thailand-UK Community    Thailand-UK Forums  Hop To Forum Categories  Commerce  Hop To Forums  TV, Computers and Internet    Identifying the source of an email

Moderators: Conrad, GTG, John, rolyshark, Tobias

Closed Topic Closed
Go
New
Find
Notify
Tools
-star Rating Rate It!  Login/Join 
Forum Regular
Picture of richardb
Posted
I act for a burmese pro democracy activist who has a yahoo group and a simple website. I need to show that the Burmese Junta and their agents are aware of his activities. He tells me that his email is often targeted with viruses and such like and he thinks its from the Burmese Authorities. For my part his inbox looks not to different in my view to most with a collection of junk with atachments you would be mad to click on. My understanding of these things is that virus attacks are likely to come from " slave " computers which would not likely be in Burma. He also reports emails on Anti govt burmese sites which purport to come from him but do not and whos contents are calculated to discredit him. This seems a more fruitful possible line of enquiry. Is there an easy way for a non Techie like me to find who really sent them and to identify country of origin.

Thanks
 
Posts: 1189 | Location: London | Registered: 06 October 2002Edit or Delete MessageReport This Post
Engine Room
Picture of maokaang
Posted Hide Post
Hi Richard

The key is to view full headers for the email. The originating IP address can be found within the header information, but you will need to know what you are looking for as there may be several IPs listed tracing the email's journey around the world. Only one will be the originating address.

Instructions for displaying the full header vary depending on the email software you are using. e.g. Outlook, Outlook Express, Thunderbird.


A typical header looks like this although there are many variations and the originating IP is not always as obvious:

quote:
From - Fri Oct 07 16:56:36 2005
X-Account-Key: account4
X-UIDL: 6c04de695cea6b43bccada5a7ea315c6
X-Mozilla-Status: 0003
X-Mozilla-Status2: 00000000
Return-path:
Envelope-to: webmaster@thailand-uk.com
Delivery-date: Fri, 07 Oct 2005 08:51:25 -0700
Received: from mail by da035.wh01.infopop.net with spam-scanned (Exim 4.42)
id 1ENuVI-0007SZ-OV
for webmster@thailand-uk.com; Fri, 07 Oct 2005 08:51:25 -0700
Received: from webmail-outgoing2.us4.outblaze.com ([205.158.62.67] helo=webmail-outgoing.us4.outblaze.com)
by da035.wh01.infopop.net with esmtp (Exim 4.42)
id 1ENuVI-0007SW-CL
for webmaster@thailand-uk.com; Fri, 07 Oct 2005 08:51:24 -0700
Received: from unknown (unknown [192.168.9.180])
by webmail-outgoing.us4.outblaze.com (Postfix) with QMQP id 9F92F18001D9
for ; Fri, 7 Oct 2005 15:51:23 +0000 (GMT)
X-OB-Received: from unknown (203.86.166.63)
by wfilter.us4.outblaze.com; 7 Oct 2005 15:51:23 -0000
Received: by ws3.hk5.outblaze.com (Postfix, from userid 1001)
id D593A102FD6; Fri, 7 Oct 2005 15:51:22 +0000 (GMT)
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain; charset="iso-8859-1"
MIME-Version: 1.0
From: "j smith" someaddress@bkkmail.com
To: webmaster@thailand-uk.com
Date: Fri, 07 Oct 2005 23:51:22 +0800
Subject: cannot see
Received: from [212.219.188.4] by ws3.hk5.outblaze.com with http for
someaddress@bkkmail.com; Fri, 07 Oct 2005 23:51:22 +0800
X-Originating-Ip: 212.219.188.4
X-Originating-Server: ws3.hk5.outblaze.com
Message-Id: 20051007155122.D593A102FD6@ws3.hk5.outblaze.com
X-Spam-Checker-Version: SpamAssassin 3.0.1 (2004-10-22) on
da035.wh01.infopop.net
X-Spam-Level:
X-Spam-Status: No, score=0.0 required=7.5 tests=none autolearn=ham
version=3.0.1
(The sender's email address has been altered in the above example)

Once you have the originating IP address you then need to do a WHOIS search on the internet to see who the Internet provider is. One of many places you can do this is http://www.samspade.org/


In the above example the email originated from 212.219.188.4 which is:

fpnetworkbox.leicestercollege.ac.uk
descr: Leicester College
country: GB

So, if the person sending the above email had said they were in Thailand, they'd be telling porkies.

Smiler


Paul พอล

เข้าเมืองตาหลิ่วต้องหลิ่วตาตาม
 
Posts: 4856 | Location: เมืองขอนแก่น ประเทศไทย | Registered: 10 September 2002Edit or Delete MessageReport This Post
Forum Addict
Posted Hide Post
Paul am I right in assuming that if an email was sent from hotmail, yahoo or one of the other free on line email servers the IP would not be correct for the originating country ?
 
Posts: 1479 | Registered: 25 May 2003Edit or Delete MessageReport This Post
Engine Room
Picture of maokaang
Posted Hide Post
Wrong assumption I'm afraid, sending via webmail does not hide the originating IP address. Within the header of the email there will be a whole load of other IP addresses listed (e.g. US Hotmail servers), but the originating IP of the computer you sent the message from will also be there.

The above example was sent to me using BKKmail, a webmail service using Outblaze mail servers in Hong Kong, so there are several Hong Kong IP addresses in the header. However, the Internet Provider of the computer used to send the message is still listed, in the above example that was Leicester College in the UK. The same goes for mail sent using Hotmail, Yahoo, etc.

Regards


Paul พอล

เข้าเมืองตาหลิ่วต้องหลิ่วตาตาม
 
Posts: 4856 | Location: เมืองขอนแก่น ประเทศไทย | Registered: 10 September 2002Edit or Delete MessageReport This Post
Lee
Admin
Picture of Lee
Posted Hide Post
Stop giving our secrets away Paul.
There could be a troll watching!

Usually is Nod

Lee Wink



 
Posts: 4224 | Location: North Wales | Registered: 11 September 2002Edit or Delete MessageReport This Post
ash
Only Me
Picture of ash
Posted Hide Post
Of course if the email is sent via a remote desktop connection to a computer in another country then the originating IP address would be hidden , but we are all honest chaps here Smiler

ash


We all live under the same sky, but we don’t all have the same horizon.- Konrad Adenauer
 
Posts: 3469 | Location: Alsace - France | Registered: 11 May 2004Edit or Delete MessageReport This Post
Engine Room
Picture of maokaang
Posted Hide Post
quote:
Of course if the email is sent via a remote desktop connection to a computer in another country then the originating IP address would be hidden , but we are all honest chaps here
You've got to be a bit smarter than that to get away with it, but there are ways to, on the face of it, remain anonymous, but we won't go into that here. Wink


Paul พอล

เข้าเมืองตาหลิ่วต้องหลิ่วตาตาม
 
Posts: 4856 | Location: เมืองขอนแก่น ประเทศไทย | Registered: 10 September 2002Edit or Delete MessageReport This Post
ผู้ช่วยไกล่เกลี่ย
Picture of rolyshark
Posted Hide Post
quote:
Stop giving our secrets away Paul.

I knew that gobbledegook looked familiar Smiler Thumbs Up


Steve aka Rolyshark
 
Posts: 4635 | Location: Derby UK | Registered: 18 September 2002Edit or Delete MessageReport This Post
Forum Regular
Picture of richardb
Posted Hide Post
Cheers all I am off to do some sloothing. I remember last time I was in Burma it was the fourth day I had crossed the border at 8am. The Immigration officer asks me why I keep visiting. I just answered " I just love Myanmar too much " Angel

Richard
 
Posts: 1189 | Location: London | Registered: 06 October 2002Edit or Delete MessageReport This Post
 Previous Topic | Next Topic powered by eve community  

Closed Topic Closed

Home Page    Thailand-UK Community    Thailand-UK Forums  Hop To Forum Categories  Commerce  Hop To Forums  TV, Computers and Internet    Identifying the source of an email

Copyright ลิขสิทธิ์ ©2002-2008 Thailand-UK.com - All rights reserved.
« Book Hotels in Thailand Online Now »
Bangkok
Cha Am
Chiang Mai
Chiang Rai
Chumphon
Hat Yai
Hua Hin
Isaan
Kanchanaburi
Koh Chang
Koh Phangan
Koh Samui
Koh Tao
Krabi
Mae Hong Son
Pattaya
Phuket
Rayong
South Thailand
Trat
Indonesia
Singapore