LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-05-2006, 03:20 AM   #1
ignhie
LQ Newbie
 
Registered: Jul 2005
Location: jakarta
Posts: 5

Rep: Reputation: 0
Avoiding email hijacking


Hi,
I'm using qmail in our system. Once we authenticated (using LDAP) to the mail server then we could send and receive email. But on the other hand if someone eg person A login to the mail system and then once he is authenticated then he can send email using for instance B@aaa.com instead of his email id which is A@aaa.com.
Is there any way that I can protect this to happen ? So A can only send email using his identity instead of other person identity ?


Thanks for the help
 
Old 04-06-2006, 05:38 AM   #2
timmeke
Senior Member
 
Registered: Nov 2005
Location: Belgium
Distribution: Red Hat, Fedora
Posts: 1,515

Rep: Reputation: 61
Which address is "faked" by A?
The envelope address or the address in the "From:" header?
The first normally is hard and maybe even not allowed.
The latter is often relatively easy and rather harmless.
 
Old 04-07-2006, 01:59 AM   #3
ignhie
LQ Newbie
 
Registered: Jul 2005
Location: jakarta
Posts: 5

Original Poster
Rep: Reputation: 0
thx,
A is faking B email address (which A & B is valid email address in the LDAP). The "From:" will be displayed as from B@aaa.com.
thx
 
Old 04-07-2006, 02:22 AM   #4
timmeke
Senior Member
 
Registered: Nov 2005
Location: Belgium
Distribution: Red Hat, Fedora
Posts: 1,515

Rep: Reputation: 61
So, it's just the "From:" header that is altered? I doubt if you can change that.
There are many possibilities to customize the from: header.
For instance, using command line sendmail, Tcl, possibly also PhP, etc.
So I doubt you can control them all...
For instance, using Tcl, you can easily send mails out to any mail server that accepts SMTP connections and you can set the From: header to whatever you want.

I suppose the only thing you can do is try to limit the access to mail servers, in order to make all mails pass via a few mail servers under your control. You may be able to configure the servers to modify the faked from: addresses (for instance, setting them equal to the envelope sender address).

In any case, I wouldn't worry too much about faked from: headers as long as the envelope sender address still indicates who really sent the mail.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
php4: avoiding eval() Nathanael Programming 5 10-17-2005 06:00 AM
Avoiding rewind & eject consty Linux - General 7 06-07-2005 07:24 AM
Avoiding pitfalls... tracedroute Slackware - Installation 6 05-09-2004 04:54 PM
Testing and avoiding University firewalls jago25_98 Linux - Networking 4 12-11-2003 04:19 PM
monolithic kernel, avoiding lkms? m00 Linux - Security 3 11-11-2003 02:08 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:29 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration