Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




fulldisclosure logo Full Disclosure mailing list archives

RE: a question about e-mails
From: "Rainer Gerhards" <rgerhards () hq adiscon com>
Date: Thu, 26 Feb 2004 17:55:39 +0100

Do a "REPLY ALL" (MS Outlook/express)
All the email ids in TO, CC, BCC will be displayed.

BCC will not. The reason is that BCC recipients are only in the
envelope, which should not be seen by the MUA (mail user agent, e.g.
outlook). All non-broken implementations do this right (and I don't know
a broken implementation that does *this* wrong).

The only way you can see BCC recipients is if you

a) have access to the first server used to transmit the message
   (the sender's server)
b) this server has detailled-enough logging active
c) you can access & review the logs

Subsequent servers (recipient's servers) do NOT have full BCC
information, not even in their logs. This is because the sending server
does not mention envelope recipients that are not on the target server.

For the same reasons, envelope recipients and body recipients ("TO:",
"CC:") can be totally differnet (yet another way to fake things).

All of this, of course, is nicely documented in the SMTP RFCs (which I
don't all know by number - RFC 822 may be a good starting point, google
may be another ;)).

HTH
Rainer

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]