Re: [PEPr] Comment on Payment::Ewire_Payment
| From: | Asbjørn Sloth Tønnesen | Date: | Wed, 30 Mar 2005 20:47:43 +0000 |
| Subject: | Re: [PEPr] Comment on Payment::Ewire_Payment | ||
| References: | 1 2 3 4 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-36995@lists.php.net to get a copy of this message | ||
On Wed, 2005-03-30 at 11:02 -0500, Philippe Jausions wrote:
> [..]
>
> Still, e-mail notification is not secure, regardless of how many headers
> you parse. E-mail headers can be forged as well.
Yes, but the recevied headers are added on the way from the sender to
the receipient.
Lets follow an example mails way though the internet:
1) @217.116.227.145
When the mail is sent from eWIRE the mail doesn't contain any "Received"
headers.
2) @195.190.153.169
The mail is received by eWIREs SMTP server (mail.ngdc.net) and it
appends the following header:
> Received: from app (unknown [217.116.227.145])
> by mail.ngdc.net (Postfix) with ESMTP id 2688748056
> for <ewire@cf-lan.dk>; Wed, 16 Mar 2005 00:21:31 +0100 (CET)
3) @217.61.223.78
The mail is received by my mail server and it appends the following
header:
> Received: from mail.ngdc.net (mail.ngdc.net [195.190.153.169])
> by asbjorn.biz (Postfix) with ESMTP id 70C2716C05
> for <ewire@cf-lan.dk>; Wed, 16 Mar 2005 00:21:31 +0100 (CET)
So if I trust my mail server, I can rely on this information
4) @127.0.0.1
My virus scanner appends the following header:
> Received: from asbjorn.biz ([127.0.0.1])
> by localhost (tux [127.0.0.1]) (amavisd-new, port 10024) with ESMTP
> id 29753-08; Wed, 16 Mar 2005 00:21:31 +0100 (CET)
5) @127.0.0.1
My mail server recieves the mail from my virus scanner, adds:
> Received: from localhost (localhost [127.0.0.1])
> by asbjorn.biz (Postfix) with ESMTP id EC0EF16C10;
> Wed, 16 Mar 2005 00:21:31 +0100 (CET)
and pipe it to my script, which only allows the following addresses to
be used in the "Recieved" headers:
>From Ewire.php
> // Who are we trusting
> $allowed_ip_addresses = array(
> 'ewire app' => '217.116.227.145',
> 'ewire host' => '195.190.153.169',
> 'localhost' => '127.0.0.1');
If an unauthorized ip address apears in the recieved headers, it will
result in an error, which I in my example, means the script would sent
me an mail with the subject "Invalid ip in route: ip_address".
Can you give an example on how you will you break this control?
> Of course when you
> manually check the balance of the account, then you'll see it was a
> fraudulent payment notification, but the whole point is to automate a
> back-end, right?
In my setup im using a another address for the script and then from my
ewire address forwarding it to my mailbox and the script. That way I
would always have a copy, just in case.
> Yes, a signed e-mail would be much better. But this means all the users
> of eWire would need to have a public key, which will most likely not be
> the case. Although, this can be enforced by the package itself. That
> could be a good way to up the security.
No, if it is signed with eWIREs private key, everybody who have the
public key, is able to decrypt the file. I haven't heard from eWIRE
since I made the suggesion, but Lasse Rungholm (Sales/Marketing, eWIRE),
sounded to like the idea in the phone, and would bring it up on the
weekly development meeting. My point is that, "reveived"-control is not
the best solution, but I think it is secure enogh for now. Then it must
be up to another release to add support for signined xml documents.