Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Security-Basics
[Top] [All Lists]

Re: OT: IP of the originating machine from a gmail email

Subject: Re: OT: IP of the originating machine from a gmail email
Date: 31 Dec 2007 14:08:29 -0000
I've always wanted to get around to testing this with Gmail, but I've seen 
Hotmail and Yahoo leak the originating IP in the past (not sure if it still 
does). Here's my testing:

1) Send an email from your gmail account to some other account you control. Use 
the web interface when composing the email. Check the headers when you get it. 
I don't expect this to show anything except Gmail's server IP.

2) Send an email from your gmail account to some other account you control. Use 
a fat email client (Outlook, Eudora...) to compose the message and connect to 
Gmail to send it. With other services, this sometimes leaks the IP of the 
sender in the header info.


Or ask Google if you have a legal reason.

You could also be a bit more active. Reply to the Gmail account you want to 
probe, but include an embedded image hosted on some remote server. When the 
mail message is viewed, most people should still auto-load images and you'll 
see the originating IP in your logs. This is not foolproof; you need a web 
server, need them to check from an identifying location, need them to view 
images, and so on. This should work better if you Google the email address and 
try to appeal to the interests of the user based on the resulting research...



<- snip ->
Hello,

I was wondering if there is a way to get the IP address of the machine
that was used to compose an email that was sent using gmail?

saqib
http://www.quantumcrypto.de/dante/

<Prev in Thread] Current Thread [Next in Thread>