Received from local host 127.0.0.1 ???????


  1. Posts : 49
    Win 7 HP 64 bit
       #1

    Received from local host 127.0.0.1 ???????


    I've been plauged by trojans and worms in spoofed emails with forged headers. So, I now at least look at the email headers now, even if I do not understand all of it - I had this in the header of 2 emails today:

    "from localhost ([127.0.0.1] helo=sfs-ml-2.v29.ch3.sourceforge.com) by sfs-ml-2.v29.ch3.sourceforge.com with esmtp (Exim 4.74) (envelope-from <sleuthkit-users-bounces@lists.sourceforge.net>) id 1Q47OU-00008s-Gd; Mon, 28 Mar 2011 08:01:46 +0000"

    What does this mean? Is this a spoofed email header?

    Thanks in advance for your help!
      My Computer


  2. Posts : 5,056
    Windows 7 x64 pro/ Windows 7 x86 Pro/ XP SP3 x86
       #2

    Sleuthkit is a collection of open source forensic tools. Did you at any time download those or subscribe to their mailing lists?

    Old Nabble - The Sleuth Kit forum

    The Sleuth Kit | Download The Sleuth Kit software for free at SourceForge.net

    You could just block mail from that sender.
      My Computer


  3. Posts : 49
    Win 7 HP 64 bit
    Thread Starter
       #3

    I didn't look further than the "received from" IP


    Yes, I did subscribe to the Sleuthkit mailings. I didn't look past the "local host" part -

    So, even if the "received from" portion of the header says "from local host 127.0.0.1"

    this by itself doesn't indicate mal/spy ware? I'd just never seen that before, and just assumed it had to be incorrect.

    I'm paranoid now because of all the forged emails I've had in the past with trojans in them.
      My Computer


  4. Posts : 5,056
    Windows 7 x64 pro/ Windows 7 x86 Pro/ XP SP3 x86
       #4

    The "from localhost" is a common issue, has to do something with the way the mail is relayed and how the hosts file is setup and what software is used. But AFAIK, it doesnt indicate any malware. If you want to get into the details, post in the networking subforum.
      My Computer


  5. Posts : 391
    Windows 7 Professional x64 Backtrack 4 R2
       #5

    joecrash said:
    "from localhost ([127.0.0.1] helo=sfs-ml-2.v29.ch3.sourceforge.com) by sfs-ml-2.v29.ch3.sourceforge.com with esmtp (Exim 4.74) (envelope-from <sleuthkit-users-bounces@lists.sourceforge.net>) id 1Q47OU-00008s-Gd; Mon, 28 Mar 2011 08:01:46 +0000"
    !
    I really wouldn't be concerned, if you take a closer look you can see what its doing.

    When it says localhost ([127.0.0.1] it is talking about the loopback address on your machine.

    by sfs-ml-2.v29.ch3.sourceforge.com with esmtp this is the mail server address which uses esmtp (a mail protocol) to send it.

    (Exim 4.74) is the mail server which sent the mail

    sleuthkit-users-bounces@lists.sourceforge.net is the email adress it sent from

    Mon, 28 Mar 2011 08:01:46 is just your date/time stamp for the email.

    Nothing out of the ordinary here, all this text is in every email, you just normally cant see it.
      My Computer


  6. Posts : 49
    Win 7 HP 64 bit
    Thread Starter
       #6

    Thank you


    Thanks for looking at that, it lessens my paranoia a bit!

    I'll have to research email headers and forging them to be able to pick the bad ones out in the future, but at least I know I'm OK for now.
    Thanks Again.
      My Computer


  7. Posts : 391
    Windows 7 Professional x64 Backtrack 4 R2
       #7

    Glad i could be of some assistance. :)
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 21:08.
Find Us