Re: [PEPr] Comment on Payment::Ewire_Payment

From: Date: Wed, 30 Mar 2005 20:47:43 +0000
Subject: Re: [PEPr] Comment on Payment::Ewire_Payment
References: 1 2 3 4  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-36995@lists.php.net to get a copy of this message
On Wed, 2005-03-30 at 11:02 -0500, Philippe Jausions wrote: > [..] > > Still, e-mail notification is not secure, regardless of how many headers > you parse. E-mail headers can be forged as well. Yes, but the recevied headers are added on the way from the sender to the receipient. Lets follow an example mails way though the internet: 1) @217.116.227.145 When the mail is sent from eWIRE the mail doesn't contain any "Received" headers. 2) @195.190.153.169 The mail is received by eWIREs SMTP server (mail.ngdc.net) and it appends the following header: > Received: from app (unknown [217.116.227.145]) > by mail.ngdc.net (Postfix) with ESMTP id 2688748056 > for <ewire@cf-lan.dk>; Wed, 16 Mar 2005 00:21:31 +0100 (CET) 3) @217.61.223.78 The mail is received by my mail server and it appends the following header: > Received: from mail.ngdc.net (mail.ngdc.net [195.190.153.169]) > by asbjorn.biz (Postfix) with ESMTP id 70C2716C05 > for <ewire@cf-lan.dk>; Wed, 16 Mar 2005 00:21:31 +0100 (CET) So if I trust my mail server, I can rely on this information 4) @127.0.0.1 My virus scanner appends the following header: > Received: from asbjorn.biz ([127.0.0.1]) > by localhost (tux [127.0.0.1]) (amavisd-new, port 10024) with ESMTP > id 29753-08; Wed, 16 Mar 2005 00:21:31 +0100 (CET) 5) @127.0.0.1 My mail server recieves the mail from my virus scanner, adds: > Received: from localhost (localhost [127.0.0.1]) > by asbjorn.biz (Postfix) with ESMTP id EC0EF16C10; > Wed, 16 Mar 2005 00:21:31 +0100 (CET) and pipe it to my script, which only allows the following addresses to be used in the "Recieved" headers: >From Ewire.php > // Who are we trusting > $allowed_ip_addresses = array( > 'ewire app' => '217.116.227.145', > 'ewire host' => '195.190.153.169', > 'localhost' => '127.0.0.1'); If an unauthorized ip address apears in the recieved headers, it will result in an error, which I in my example, means the script would sent me an mail with the subject "Invalid ip in route: ip_address". Can you give an example on how you will you break this control? > Of course when you > manually check the balance of the account, then you'll see it was a > fraudulent payment notification, but the whole point is to automate a > back-end, right? In my setup im using a another address for the script and then from my ewire address forwarding it to my mailbox and the script. That way I would always have a copy, just in case. > Yes, a signed e-mail would be much better. But this means all the users > of eWire would need to have a public key, which will most likely not be > the case. Although, this can be enforced by the package itself. That > could be a good way to up the security. No, if it is signed with eWIREs private key, everybody who have the public key, is able to decrypt the file. I haven't heard from eWIRE since I made the suggesion, but Lasse Rungholm (Sales/Marketing, eWIRE), sounded to like the idea in the phone, and would bring it up on the weekly development meeting. My point is that, "reveived"-control is not the best solution, but I think it is secure enogh for now. Then it must be up to another release to add support for signined xml documents.

« previous php.pear.dev (#36995) next »