[Raw Msg Headers][Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Crippling Received: headers



> > Matti,
> > 
> > attached is a message from bugtrack about a way to make sendmail produce
> > Received: header without information about the sender host address.
> > I appears that Zmailer is vulnerable to the same type of attack.
> 
>      Well, depends on the version.
>      Earlier ones were susceptible to it to some extent, but these
>      lattest ones are not.

..50-s2 did not display the helo paramter, and did not display the peer
address information.  The Received: header looked like this:

Received: by thanatos.sovam.com with ESMTP id <45817-21624>; Wed, 27 May 1998
21:57:20 +0400

(I have exact example lost, sorry).

Eugene