ietf-asrg
[Top] [All Lists]

RE: [Asrg] Spammer proxies using legitamate mail relays

2005-02-16 05:55:14
HKEY_CURRENT_USER -> Software -> Microsoft -> Internet Mail and News
-> Mail:
DefaultSMTPServer

This is not a standard value in Windows. It may be common, but you can't
rely on it. I've just tested 3 systems and found it on none. 

Windows, Outlook, Outlook Express and other mail clients change the
location of their server values even from version to version. This is
far from an insurmountable obstacle, but it makes the job non-trivial.
In all likelihood the encoding in the registry for the passwords changes
from version to version. Outlook 2003 doesn't store even the SMTP server
in plain text or an obvious location anymore.

But it can be done. See Passware (http://www.lostpassword.com/) for
programs that can crack cached credentials for almost anything, and I've
specifically tested it against SMTP AUTH credentials.



_______________________________________________
Asrg mailing list
Asrg(_at_)ietf(_dot_)org
https://www1.ietf.org/mailman/listinfo/asrg