RE: Re[2]: Help - How to unwind an SRS address?

Mark <[email protected]> Sun, 21 Nov 2004 03:02:01 GMT
Newsgroups gmane.mail.spam.srs.general
Organization Asarian-host
Message-ID <[email protected]>
Mark wrote:

> > I have never had the need to determine the pre-rewritten sender in
> > a foreign SRS address, yet.

Seth Goodman wrote:

> I don't recall whether or not the SRS spec mentioned this, but the
> destination gateway MTA or its MDA should unwrap an SRS address before
> writing the Return-Path: header.

The destination gateway MTA can only perform a pseudo-unwrap, of
course (and then only for non-database SRS0 addresses). The database
SRS0 addresses, btw, allow for a near zero-tolerance playback defense.
I am not sure exactly how thread-safe MLDBM (DB_File) calls really
are; or how well and easily you can lock access to the database (for
multiple applications, such as Milter and LDA trying to access
BerkeleyDB at the same time). Maybe I will write a MySQL interface for
it. :)

> The reason for not exposing an SRS address to the end user is to
> reduces the possibility of an SRS signed address being harvested and
> used to create forged bounces to the SRS0 rewriting forwarder, who
> will accept the forgery and deliver it to the original sender.  The
> original sender can only be spammed this way until the SRS0 signature
> expires, so it is not a major problem.

Yes. The problem is, of course, programs like SA, who like to have a
go at SPF too. With no SRS 'original' Return-Path to be found any
more, they are stuck (I'm sure something can be done with HELO,
in those cases; but that offers no real substitute for per-virtual
domain SPF policies).

> > Any foreign SRS entity can be checked "as is" (for callbacks and
> > such, if you had those in mind). In fact, 'unrolling' them first, and
> > then do remote checks on them, may even be worse.

> If the original sender rewrites all return-paths as SRS0 addresses to
> accomplish SES, a callback to the unsigned address should fail.

Callbacks to such 'unrolled' addresses would fail here.

> Callback requests to the signed address, OTOH, should succeed.

Indeed. That is why the OP, if he had callbacks in mind, best do them
on the SRS addresses "as is". It is the responsibility of the sending MTA
to deal with them on return.

- Mark 
 
        System Administrator Asarian-host.org
 
---
"If you were supposed to understand it,
we wouldn't call it code." - FedEx