RE: Re[2]: Help - How to unwind an SRS address?
"Seth Goodman" <[email protected]> Sat, 20 Nov 2004 20:12:49 -0600
| Newsgroups | gmane.mail.spam.srs.general |
|---|---|
| Message-ID | <[email protected]> |
> From: Mark > Sent: Saturday, November 20, 2004 6:12 PM <...> > I have never had the need to determine the pre-rewritten sender in > a foreign SRS address, yet. I don't recall whether or not the SRS spec mentioned this, but the destination gateway MTA or its MDA should unwrap an SRS address before writing the Return-Path: header. It is undesirable to expose SRS addresses. This is an issue only for hostile recipients, or for (stupid) recipients that might forward the complete set of received headers to a hostile third party. Presumably, you don't send mail to hostile or stupid recipients, but Ben Franklin's admonition that "an ounce of prevention is worth a pound of cure" applies here. [Apologies to the rest of the world for the archaic units, but "28.4 grams of prevention is worth 0.454 kilograms of cure" is devoid of literary value.] The reason for not exposing an SRS address to the end user is to reduces the possibility of an SRS signed address being harvested and used to create forged bounces to the SRS0 rewriting forwarder, who will accept the forgery and deliver it to the original sender. The original sender can only be spammed this way until the SRS0 signature expires, so it is not a major problem. > Any foreign SRS entity can be checked > "as is" (for callbacks and such, if you had those in mind). In fact, > 'unrolling' them first, and then do remote checks on them, may even > be worse. If the original sender rewrites all return-paths as SRS0 addresses to accomplish SES, a callback to the unsigned address should fail. Callback requests to the signed address, OTOH, should succeed. -- Seth Goodman