Tag Archive for: sniff

What all the stuff in email headers means—and how to sniff out spoofing

Come to think of it, maybe you shouldn't open this one at all.

Enlarge / Come to think of it, maybe you shouldn’t open this one at all. (credit: Aurich / Thinkstock)

I pretty frequently get requests for help from someone who has been impersonated—or whose child has been impersonated—via email. Even when you know how to “view headers” or “view source” in your email client, the spew of diagnostic wharrgarbl can be pretty overwhelming if you don’t know what you’re looking at. Today, we’re going to step through a real-world set of (anonymized) email headers and describe the process of figuring out what’s what.

Before we get started with the actual headers, though, we’re going to take a quick detour through an overview of what the overall path of an email message looks like in the first place. (More experienced sysadmin types who already know what stuff like “MTA” and “SPF” stand for can skip a bit ahead to the fun part!)

From MUA to MTA, and back to MUA again

The basic components involved in sending and receiving email are the Mail User Agent and Mail Transfer Agent. In the briefest possible terms, an MUA is the program you use to read and send mail from your own personal computer (like Thunderbird, or Mail.app, or even a webmail interface like Gmail or Outlook), and MTAs are programs that accept messages from senders and route them along to their final recipients.

Read 40 remaining paragraphs | Comments

Biz & IT – Ars Technica

Rogue CBP Agent Decided To ‘Drain The Swamp’ By Tracking Down A Journalist To Sniff Out Her Sources

The DOJ has decided it can safely threaten First Amendment protections, so long as it’s done in the pursuit of leakers. The Trump Administration has leaked like no other, prompting AG Jeff Sessions to triple-up on former president Obama’s war on whistleblowers. Omelets/eggs broken, I suppose, if the end goal is dialing back leaks to only the ones the administration approves of.

It’s cool to target journalists’ communications again. That’s the general mood of the DOJ, which slapped itself on the wrist during Eric Holder’s tenure for hoovering up AP journalists’ communications, only to reverse course when the desire to prosecute leakers surpassed its desire to not look like a thuggish force of government oppression.

The indictment of Senate Intelligence Committee advisor James Wolfe contained a lot of journalists’ communications and metadata obtained from several sources, including service providers these journalists used. This was disturbing enough, suggesting the new normal for leak investigations is targeting members of the press to work backwards to their anonymous sources.

But there’s even more shadiness going on than is observable from that single indictment. A self-appointed freedom fighter with the unbelievable last name of Rambo was apparently trying to suss out journalist Ali Watkins’ sources. (Watkins’ email and communications data were subpoenaed during the Wolfe investigation.) The first hints that something weird and disturbing was going on behind the scenes was published by The Washington Post. It detailed the apparently rogue (and illegal) actions of a government employee prior to the delivery of the Wolfe indictment.

The actions of a Customs and Border Protection agent who confronted a reporter covering national security issues about her confidential sources are being examined by the CBP’s Office of Professional Responsibility, the agency said in a statement Tuesday.

The agent, Jeffrey A. Rambo, contacted journalist Ali Watkins last June as the Trump administration was ramping up its investigations of unauthorized leaks to reporters, and he identified himself as a government agent.

Rambo met with Watkins at a restaurant in Washington after initially contacting her by email. A reporter taking such a meeting with a potential source would not be unusual.

But after he arrived, Rambo said the administration was eager to investigate journalists and learn the identity of their confidential sources to stanch leaks of classified information. He questioned Watkins broadly about her reporting and how she developed information, according to the people familiar with the incident, who spoke on the condition of anonymity to discuss a sensitive matter.

The “examination” is now an official investigation, the New York Times reports. More details about Rambo’s actions have surfaced, suggesting flagrant abuse of sensitive government databases for the purpose of tracking down Watkins and pressuring her to divulge her sources.

The agent, Jeffrey A. Rambo, who usually worked in the San Diego area, was temporarily assigned at the time to the National Targeting Center, a facility in Sterling, Va., operated by Customs and Border Protection that stores data on the travel of millions of Americans and foreigners. Such information is supposed to be used only under strict rules by immigration and law enforcement officials.

Now the Department of Homeland Security’s inspector general and investigators from the border agency are examining whether Mr. Rambo used the travel data improperly or illegally and whether anyone else was involved.

It doesn’t appear anyone directed Rambo to meet with Watkins and attempt to discover the identities of her sources. From the statements given to the New York Times, it appears Rambo was simply a self-starter bursting with misdirected gumption.

It remains unclear whether Mr. Rambo handled or heard about an official F.B.I. request to the center for Mr. Wolfe’s travel records, and, if so, whether that led to the discovery that Ms. Watkins was his traveling companion. According to Ms. Watkins’s accounts, Mr. Rambo spoke with enthusiasm to her about Mr. Trump’s crackdown on leaks, telling her that “we’re finally going to be able to drain the swamp,” raising the possibility that he had searched the database for her records on his own initiative.

It really doesn’t matter whether Rambo felt draining the swamp was his own personal mission or someone on the inside suggested he check the situation out. Either way, it’s an abuse of Rambo’s position and access. The DOJ started screwing the pooch with its demand for journalists’ records and communications and Rambo came along to botch the job and clumsily bury the canine after performing a hit-and-run on his own career. This is scary stuff and it’s not being helped by the anti-journalist attitude being fostered by the man at the top of the governmental food chain.

Permalink | Comments | Email This Story

Techdirt.

Internet helps creep who wants to meet Taylor Swift so he can sniff her hair – Daily Caller

Internet helps creep who wants to meet Taylor Swift so he can sniff her hair
Daily Caller
NEW YORK, NY – MAY 06: Taylor Swift attends the Costume Institute Gala for the "PUNK: Chaos to Couture" exhibition at the Metropolitan Museum of Art on May 6, 2013 in New York City. (Photo by Andrew H. Walker/Getty Images for People.com). Tweet.

and more »

flame malware – read more