RE: Filtering email headers generated from internal network (Sensible?)

From: Eyal Udassin (eyal_at_swiftcoders.com)
Date: 05/10/05

  • Next message: Omar Herrera: "RE: DDos within a pentest"
    To: "'Bipin Gautam'" <visitbipin@hotmail.com>, <pen-test@securityfocus.com>
    Date: Tue, 10 May 2005 01:27:03 +0200
    
    

    Hello Bipin,

    Since the cost of implementing a filter to remove the MIME fields you
    mentioned is very low, I highly recommend it.
    This is very similar to recommending to remove the server field of the HTTP
    response in web servers.

    From my point of view, you can only gain from filtering this data.

    Best regards,
    Eyal Udassin - Swift Coders
    POB 1596 Ramat Hasharon, 47114
    972+547-684989
    eyal@swiftcoders.com
    www.swiftcoders.com

    -----Original Message-----
    From: Bipin Gautam [mailto:visitbipin@hotmail.com]
    Sent: Monday, May 09, 2005 5:36 PM
    To: pen-test@securityfocus.com
    Subject: Filtering email headers generated from internal network (Sensible?)

    Is it sensible to filter extra email headers in the gateway generated from
    your internal network before it leaves your server, so that Information
    like... User-Agent:, X-Virus-Scanned:, and those EXTRA hopps of Received
    from: (headers........) won't leak out, which could be a valuable
    information for a potential intruder. Moreover the trouble multiplies if a
    software exploit is realesed before patch. It is kinda Security by
    obscurity. But if it buys you some extra time to act isn't is sensible to
    impliment or just too paranoid?

    drop your views,
    Bipin Gautam
    http://bipin.sosvulnerable.net/


  • Next message: Omar Herrera: "RE: DDos within a pentest"

    Relevant Pages

    • Re: Building a mail server
      ... qmail uses Maildir exclusively. ... vpopmail supports virtual domains and you can set catch-all accounts ... > filtering to happen on the server so it's already filtered no matter what MUA ...
      (Debian-User)
    • Re: Slow Logon related to groups - Update!
      ... Sent update to server: 192.1.1.1 ... Group Policy processing aborted. ... Filtering: Denied ...
      (microsoft.public.windows.server.sbs)
    • Re: SOPHOS Antivirus
      ... > This one feature can eliminate 99% of the virus infected inbound email ... By definition a firewall has no mail filtering function. ... > updates for every 4 hours on the server and have the server push the ... > updates to the desktops. ...
      (alt.computer.security)
    • Re: SPAM and Junk Email
      ... If you have recipient filtering enabled under the Global settings, ... that you have also enabled it on the properties of the SMTP Virtual Server, ...
      (microsoft.public.exchange.admin)
    • Re: [SLE] cups/ printing problem
      ... > I'm using suse 9.1 here on our production server with samba running. ... I guess that it is the CUPS filtering system which gets somehow ... JPEG) to the print server (to a print queue via LPD ... Regarding the plain data transfer from the Windows client systems ...
      (SuSE)