RE: Re[2]: Help - How to unwind an SRS address?

"Seth Goodman" <[email protected]> Sat, 20 Nov 2004 20:12:49 -0600
Newsgroups gmane.mail.spam.srs.general
Message-ID <[email protected]>
> From: Mark
> Sent: Saturday, November 20, 2004 6:12 PM

<...>

> I have never had the need to determine the pre-rewritten sender in
> a foreign SRS address, yet.

I don't recall whether or not the SRS spec mentioned this, but the
destination gateway MTA or its MDA should unwrap an SRS address before
writing the Return-Path: header.  It is undesirable to expose SRS addresses.
This is an issue only for hostile recipients, or for (stupid) recipients
that might forward the complete set of received headers to a hostile third
party.  Presumably, you don't send mail to hostile or stupid recipients, but
Ben Franklin's admonition that "an ounce of prevention is worth a pound of
cure" applies here.  [Apologies to the rest of the world for the archaic
units, but "28.4 grams of prevention is worth 0.454 kilograms of cure" is
devoid of literary value.]

The reason for not exposing an SRS address to the end user is to reduces the
possibility of an SRS signed address being harvested and used to create
forged bounces to the SRS0 rewriting forwarder, who will accept the forgery
and deliver it to the original sender.  The original sender can only be
spammed this way until the SRS0 signature expires, so it is not a major
problem.



> Any foreign SRS entity can be checked
> "as is" (for callbacks and such, if you had those in mind). In fact,
> 'unrolling' them first, and then do remote checks on them, may even
> be worse.

If the original sender rewrites all return-paths as SRS0 addresses to
accomplish SES, a callback to the unsigned address should fail.  Callback
requests to the signed address, OTOH, should succeed.

--

Seth Goodman