<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
	<channel>
		<title>www.ritlabs.com [Topic: Security leak - Local hostname exposed to gmail]</title>
		<link>http://www.ritlabs.com</link>
		<description>New posts in Security leak - Local hostname exposed to gmail of  forum at www.ritlabs.com [www.ritlabs.com]</description>
		<language>en</language>
		<docs>http://backend.userland.com/rss2</docs>
		<lastBuildDateTag>Fri, 02 Nov 2018 10:04:47 +0200</lastBuildDateTag>		<item>
			<title>Security leak - Local hostname exposed to gmail</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic13555/message46414/">Security leak - Local hostname exposed to gmail</a></b> <i>When sending email, gmail writes down computer's local network name in email header together with public one</i> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			Thanks Daniel!<br /><br />Filed a request to them <noindex><a href="https://www.ritlabs.com/en/support/ticket_edit.php?ID=80303" target="_blank" rel="nofollow">https://www.ritlabs.com/en/support/ticket_edit.php?ID=80303</a></noindex> <br />
			<i>02 November 2018 10:04:47, <a href="http://www.ritlabs.com/en/forums/">V D</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic13555/message46414/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic13555/message46414/</guid>
			<pubDate>Fri, 02 Nov 2018 10:04:47 +0200</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
		<item>
			<title>Security leak - Local hostname exposed to gmail</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic13555/message46402/">Security leak - Local hostname exposed to gmail</a></b> <i>When sending email, gmail writes down computer's local network name in email header together with public one</i> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			I'm seeing internal server names in message headers all the time and some are actually quite entertaining. If you believe this is a security risk (and it's not required by some RFC standard), I'd recommend that you file a bug report to Ritlabs through the Support menu above. This is mainly a user-to-user forum and the developers might not see your comments, or only much later. <br />
			<i>02 November 2018 01:57:13, <a href="http://www.ritlabs.com/en/forums/">Daniel van Rooijen</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic13555/message46402/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic13555/message46402/</guid>
			<pubDate>Fri, 02 Nov 2018 01:57:13 +0200</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
		<item>
			<title>Security leak - Local hostname exposed to gmail</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic13555/message46399/">Security leak - Local hostname exposed to gmail</a></b> <i>When sending email, gmail writes down computer's local network name in email header together with public one</i> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			Using the latest The Bat Voyager 8.4.0.6 , as well as some 5-year-old version leads to this unexpected security leak. How to reproduce:<br />1) Use Gmail IMAP account in Voyager<br />2) Send an email<br />3) Sync &#91;GMAIL&#93;\Sent Mail folder with IMAP in The Bat, your message will appear there.<br />4) Open message header, you will see you local computer hostname (LOCALPC1.LOCALDOMAIN.LOCAL) together with global one, somthing like that:
====code====
<pre>Received: from LOCALPC1.LOCALDOMAIN.LOCAL (ppp183-37-15-165.pppoe.vodafone.eg &#91;183.37.15.165&#93;)
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;by smtp.gmail.com with ESMTPSA id k1-v6sm354328221lja.59.2018.11.01.12.43.31
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;for &#60;xxxxxxx@xx.xx&#62;
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;(version=TLS1_2 cipher=ECDHE-RSA-AES128-SHA bits=128/128);
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Thu, 01 Nov 2018 12:43:32 -0700 (PDT)</pre>
=============
I find this pretty much unacceptable to expose internal computer name to the public because it may contain come interesting information as well. What can be done to fix or investigate that? <br /><br />Thanks<br /><br />P.S. Your server sending emails to furum users is not vulnerable and is hardened on this issue not exposing any internal names:<br />
====code====
<pre>Received: from mail.ritlabs.com (&#91;127.0.0.1&#93;)
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;by localhost (mail.ritlabs.com &#91;127.0.0.1&#93;) (amavisd-new, port 10024)
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;with ESMTP id I5x0XOta0_kX; Thu,&nbsp;&nbsp;1 Nov 2018 22:08:56 +0200 (EET)
Received: from www.ritlabs.com (unknown &#91;10.10.11.24&#93;)
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;by mail.ritlabs.com (Postfix) with ESMTP id 7E3032601C4;
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Thu,&nbsp;&nbsp;1 Nov 2018 22:08:56 +0200 (EET)</pre>
=============
<p></p> <br />
			<i>01 November 2018 22:25:18, <a href="http://www.ritlabs.com/en/forums/">V D</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic13555/message46399/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic13555/message46399/</guid>
			<pubDate>Thu, 01 Nov 2018 22:25:18 +0200</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
	</channel>
</rss>
