[Serusers] Checking spoofed From headers

sip sip at arcdiv.com
Mon Apr 10 16:38:05 CEST 2006


Is there a way anyone can readily think of to check to see if someone using
our open proxy is calling through with a From header that attempts to fool the
recipient into thinking the call is validly from one of our users? 

Scenario is this...

While looking at the logs this morning, I noticed someone was calling a
SIPPhone user through our proxy with a From: address that LOOKED like it was a
user of ours, but using a username that doesn't actually exist. 

I'm wondering if there's anyway to check if someone is calling through us with
a From: address that looks like one of our users, but isn't. 

N.




More information about the sr-users mailing list