Spoofing absa.co.za domain?

DearHeart

Expert Member
Joined
Jun 22, 2005
Messages
1,423
I have a reasonable understanding of what spoofing is but the recent wave of SPAM confuses me. :confused: Please have a look at the header below from one of the many emails I received, it seems to genuinly come from the absa.co.za domain?

Return-path: <customer.securityalert@absa.co.za>
Envelope-to: myaddy@mydomain.co.za
Delivery-date: Fri, 29 Jan 2010 00:07:58 +0200
Received: from [217.167.39.240] (helo=sainsexch.sainsbury.fr)
by www30.jnb1.host-h.net with esmtp (Exim 4.66)
(envelope-from <customer.securityalert@absa.co.za>)
id 1NacWs-0008I4-3b
for myaddy@mydomain.co.za; Fri, 29 Jan 2010 00:07:58 +0200
Received: from User ([203.171.64.7]) by sainsexch.sainsbury.fr with Microsoft SMTPSVC(5.0.2195.5329);
Thu, 28 Jan 2010 19:07:57 +0100
From: "Absa Bank Limited"<customer.securityalert@absa.co.za>
Subject: Absa: Account Reference: (0x3d.0x38.0x4e.0xcf)
Date: Fri, 29 Jan 2010 05:03:43 +1100
 

NetSpike

Well-Known Member
Joined
Aug 27, 2006
Messages
268
No it's not genuine.

Note that the mail was received from a French domain (sainsexch.sainsbury.fr ). It's easy to spoof tre From and Reply To (Return Path) address.
 
Last edited:

gregmcc

Honorary Master
Joined
Jun 29, 2006
Messages
25,512
Correct - because of the way the SMTP protocol was designed its a simple process to spoof emails. You have to look at the flow path that the mail took to determine if its legit or not.
 

DearHeart

Expert Member
Joined
Jun 22, 2005
Messages
1,423
Thanks guys, bit more tricky than I thought. But how do I blacklist the addys since the don't really come from absa.co.za? I.e., if I block customer.securityalert@absa.co.za will it actually stop the emails from coming through? I've already blocked some of them, some gets caught in the server spam box but others still get through.
 

The_Unbeliever

Honorary Master
Joined
Apr 19, 2005
Messages
103,196
Thanks guys, bit more tricky than I thought. But how do I blacklist the addys since the don't really come from absa.co.za? I.e., if I block customer.securityalert@absa.co.za will it actually stop the emails from coming through? I've already blocked some of them, some gets caught in the server spam box but others still get through.

Don't do that - you might block legitimate emails.

1. You can use blacklisting to blacklist email servers who should not be sending spam.
2. You can add the server's IP to your own blacklist - it'll drop ALL emails originating from that server
3. Install spam filtering software to filter out spam.
 

DearHeart

Expert Member
Joined
Jun 22, 2005
Messages
1,423
Don't do that - you might block legitimate emails.

1. You can use blacklisting to blacklist email servers who should not be sending spam.
2. You can add the server's IP to your own blacklist - it'll drop ALL emails originating from that server
3. Install spam filtering software to filter out spam.

OK, I suppose I can block *@sainsbury.fr, Hetzner's blacklist does not cater for IP addresses. Outlook does catch the spam, just hate to see it there!
 

server-admins.net

Server-Admins representative
Company Rep
Joined
Oct 2, 2008
Messages
349
Hi DearHeart

The best solution would be to implement SPF. Speak to your isp about implementing this for if they do not already have it setup else ask them to review the spam weights for domains that fail SPF
 

Nerfherder

Honorary Master
Joined
Apr 21, 2008
Messages
29,703
I got that mail as well, outlook security actually removed the link and flagged it as a phishing email.
 

DearHeart

Expert Member
Joined
Jun 22, 2005
Messages
1,423
@ server-admins.net: I'm with Hetzner, their spam filter works quite well, but some of these ABSA spoofs still comes through, and they are all basically the same.
@ Nerfherder: Same here, otherwise I might have opened the email and posted my account details, personal information, Swiss bank account numbers.... not!
 

AnomalyNexus

Senior Member
Joined
Nov 29, 2009
Messages
710
With a bit of knowledge one can spoof the From field using a clean windows install without any tools.

The best way to detect phishing is to pick up the phone and call absa when in doubt.
 

server-admins.net

Server-Admins representative
Company Rep
Joined
Oct 2, 2008
Messages
349
@ DearHeart, I would drop Hetzner a quick mail - they should be able to assist.
Our spam filters mark 90% of these fake mails as Junk based on the SPF records.

Off topic, there has been an increase in attacks from these siffies that send out such mails. I make a habit of reporting them to ABSA
 
Top