I'm really not familiar with what all that info on the full header means and figuring out where the originating IP is. So, I have copied one off of an email and if any one could help me decipher what it means, I would appreciate it. I would really like to know what line is the IP address that everyone says you should compare to see if emails are coming from the same IP address. Thanks in advance for your help...Rich
Status: U
Return-Path: <laveshka_vika@mail.ru>
Received: from relay.gts.lg.ua ([195.5.28.2])
by mx-clapper.atl.sa.earthlink.net (EarthLink SMTP Server) with ESMTP id 1eYxd82mc3Nl34b0
for <rk8818@earthlink.net>; Mon, 16 Jan 2006 11:28:02 -0500 (EST)
Received: from conser (81.dc.ukrtel.net [82.207.87.81] (may be forged))
by relay.gts.lg.ua (8.12.11/8.12.8) with ESMTP id k0GGRNMs024951
for <rk8818@earthlink.net>; Mon, 16 Jan 2006 18:27:43 +0200 (EET)
(envelope-from laveshka_vika@mail.ru)
Date: Mon, 16 Jan 2006 11:06:26 +0200
From: "laveshka_vika@mail.ru (Vika S)" <laveshka_vika@mail.ru>
X-Mailer: The Bat! (v2.01) Educational
Reply-To: "laveshka_vika@mail.ru (Vika S)" <laveshka_vika@mail.ru>
Organization: mail.ru
X-Priority: 3 (Normal)
Message-ID: <16710442312.20060116110626@mail.ru>
To: rk8818@earthlink.net
Subject: from Vika
MIME-Version: 1.0
So is the closest line to the top with the IP address where it came from? In this case, line three, received from? As you can see as you go down the header, there are a couple of other IP addresses and received from on there, other than my own. So the "received" closest to the top of the header is the orginator of the email?
VNV...there's a different way to talk other than the two cans and string?!!
And,
Just for the record, I just got with the computer age and I ran a check, via www.geobytes.com/IpLocator.htm?GetLocation, on an IP address of a PC that I know to be in Zaporozhye, Ukraine.
The check tells me that this IP address is in San Fransisco, California where there is a population of 278058881 and the currency is the US Dollar!
Oh well, back to two coffee cans and a piece of string!!
Rich, this e-mail address comes from Lugansk and also note that "X-Mailer: The Bat! (v2.01) Educational" means that the girl writes from her own computer... NOT from the Internet Cafe.
Or perhaps the letter comes from an organisation's computer, if RK has received 3 letters with the same header information, RK could have found some Loo-Gangsters!
And RK,
It was always a favourite of the Loo-Gangsters to put an underscore in the email address. Did the other letters you received also have underscores in the addresses?
Martin
Here's one from a different IP, but uses an underscore. Anything look suspicious in this header?
Status: U
Return-Path: <juli_lovely@mail.ru>
Received: from mx1.mail.ru ([194.67.23.121])
by mx-bracke.atl.sa.earthlink.net (EarthLink SMTP Server) with ESMTP id 1eYwyg13z3Nl34i0
for <rk8818@earthlink.net>; Mon, 16 Jan 2006 10:45:48 -0500 (EST)
Received: from [213.179.235.118] (port=1832 helo=localhost)
by mx1.mail.ru with asmtp
id 1EyWQb-000P6y-00
for rk8818@earthlink.net; Mon, 16 Jan 2006 18:37:54 +0300
Date: Mon, 16 Jan 2006 17:29:22 +0200
From: juli_lovely <juli_lovely@mail.ru>
X-Mailer: The Bat! (v2.11 Beta/5) Business
Reply-To: juli_lovely <juli_lovely@mail.ru>
Organization: mail.ru
X-Priority: 3 (Normal)
Message-ID: <861723625.20060116172922@mail.ru>
To: "RK" <rk8818@earthlink.net>
Subject: From Julia
In-Reply-To: <027f01c61a5b$7dd8bca0$0301a8c0@toshibauser>
References: <1938762649.20060113174837@mail.ru>
<00ac01c618c1$0f6db2c0$0301a8c0@toshibauser>
<1023563223.20060114160346@mail.ru> <027f01c61a5b$7dd8bca0$0301a8c0@toshibauser>
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="----------541ED1D52DB3599"
X-ELNK-AV: 0