RE: Filtering email headers generated from internal network (Sensible?)

From: Eyal Udassin (eyal@swiftcoders.com)
Date: Mon May 09 2005 - 19:27:03 EDT


Hello Bipin,

Since the cost of implementing a filter to remove the MIME fields you
mentioned is very low, I highly recommend it.
This is very similar to recommending to remove the server field of the HTTP
response in web servers.

>From my point of view, you can only gain from filtering this data.

Best regards,
Eyal Udassin - Swift Coders
POB 1596 Ramat Hasharon, 47114
972+547-684989
eyal@swiftcoders.com
www.swiftcoders.com

-----Original Message-----
From: Bipin Gautam [mailto:visitbipin@hotmail.com]
Sent: Monday, May 09, 2005 5:36 PM
To: pen-test@securityfocus.com
Subject: Filtering email headers generated from internal network (Sensible?)

Is it sensible to filter extra email headers in the gateway generated from
your internal network before it leaves your server, so that Information
like... User-Agent:, X-Virus-Scanned:, and those EXTRA hopps of Received
from: (headers........) won't leak out, which could be a valuable
information for a potential intruder. Moreover the trouble multiplies if a
software exploit is realesed before patch. It is kinda Security by
obscurity. But if it buys you some extra time to act isn't is sensible to
impliment or just too paranoid?

drop your views,
Bipin Gautam
http://bipin.sosvulnerable.net/



This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:54:20 EDT