19.04.2013 Views

2KKUU7ita

2KKUU7ita

2KKUU7ita

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Figure 13-11:<br />

Critical<br />

information<br />

revealed in<br />

e-mail<br />

headers.<br />

Testing<br />

Chapter 13: Communication and Messaging Systems<br />

Figure 13-11 shows the header information revealed in a test e-mail I sent to<br />

my free web account. As you can see, it shows off quite a bit of information<br />

about my e-mail system:<br />

✓ The third Received line discloses my system’s hostname, IP address,<br />

server name, and e-mail client software version.<br />

✓ The X-Mailer line displays the Microsoft Outlook version I used to send<br />

this message.<br />

Countermeasures against header disclosures<br />

The best countermeasure to prevent information disclosures in e-mail headers<br />

is to configure your e-mail server or e-mail firewall to rewrite your headers,<br />

by either changing the information shown or removing it. Check your<br />

e-mail server or firewall documentation to see whether this is an option.<br />

If header rewriting is not available (or even allowed by your ISP), you still<br />

might prevent the sending of some critical information, such as server software<br />

version numbers and internal IP addresses.<br />

Capturing traffic<br />

E-mail traffic, including usernames and passwords, can be captured with a<br />

network analyzer or an e-mail packet sniffer and reconstructor.<br />

Mailsnarf is an e-mail packet sniffer and reconstructor that’s part of the dsniff<br />

package (www.monkey.org/~dugsong/dsniff/). There’s a great commercial<br />

(yet low-cost) program called NetResident (www.tamos.com/products/<br />

netresident/), too. You can also use Cain & Abel (www.oxid.it/cain.<br />

html) to highlight e-mail-in-transit weaknesses. I cover password cracking<br />

using this tool and others in Chapter 7.<br />

265

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!