TIP: Click on subject to list as thread! ANSI
echo: fidopols
to: Frank Vest
from: Jerry Schwartz
date: 2002-12-02 20:26:52
subject: NodelistGuide or FAQ

Hello, Frank...

Dec 02, 2002 at 15:21, Frank Vest wrote to Jerry Schwartz:

 FV> That is true.  on another string, let's say that your mailer
 FV> connects to my mailer via binkp (or some Fidonet protocol) to 
 FV> exchange
 FV> mail. The ISP "cop" notices that we are exchanging a
file. He grabs a
 FV> copy to find out what we are doing. Once he get the file intact, he
 FV> will find a file with 8 digits and a three digit extension that he's
 FV> wondering "what the heck is this?!?". If he tries to view
that file,
 FV> he might notice the "PKZip" in the top of the file and
realize that 
 FV> it
 FV> is a zip file. He might unzip the file and find the mail packet. He
 FV> might view that. Most likely, unless he has had experience in
 FV> Fidonet, he's gonna wonder "what the heck is this?!?" and
delete it.
 FV> :)

 FV> If he thinks that the mail bundle is an encrypted file (good
 FV> possibility), he might try to decrypt it. Gawd, that would be rich to
 FV> watch. :-))

Well, he'd see a string of IP frames (people call them packets, but they
are really frames). If he noticed the traffic was in a steady stream, or if
he paid attention to the port, he'd know it wasn't HTTP traffic and he
could potentially start capturing it. I don't know what the data stream
looks like for BinkP, but presumably the bulk of it is chunks of file. It
would take some work to assemble it into a usable file without knowing how
BinkP encapsulates it.

As somebody else said, the way to eavesdrop on email is to capture the
messages as the pass through an SMTP relay.

Most IP snooping is done to harvest addresses and ports that could be used
in an attack, or to identify "heavy talkers." The usual technique
for an ISP to make sure you aren't running a forbidden service (a news
server, for example) is to block the port altogether or to do a portscan of
your system. They don't really look at the traffic, although they might
keep track of someone who seems to be a bandwidth hog.

Regards,

Jerry Schwartz

mailto:jerryschwartz{at}comfortable.com
http://www.writebynight.com

--- Msged/NT 6.0.1
* Origin: Write by Night (1:142/928)
SEEN-BY: 633/267 270
@PATH: 142/928 906 106/1 379/1 633/267

SOURCE: echomail via fidonet.ozzmosis.com

Email questions or comments to sysop@ipingthereforeiam.com
All parts of this website painstakingly hand-crafted in the U.S.A.!
IPTIA BBS/MUD/Terminal/Game Server List, © 2025 IPTIA Consulting™.