[imp] use X-Forwarded-For: optionally

Matus UHLAR - fantomas uhlar at fantomas.sk
Mon Jan 21 14:21:59 UTC 2008


Hello,

when IMP sends a message, it adds Received: header containing address of
connecting server, or first server in X-Forwarded-For: HTTP header (if it
exists).

However if untrusted client sends whatever data in X-Forwarded-For: header,
the address (e.g. from private IP raqnge) is used. This results into useless
garbage inserted into mail headers which mey not be found in horde logs
(horde does not always log the correct IP).

Is it possible to add option either to ignore the header, or only to trust
defined set of IP addresses/ranges which would be trusted (followed)?

-- 
Matus UHLAR - fantomas, uhlar at fantomas.sk ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
Posli tento mail 100 svojim znamim - nech vidia aky si idiot
Send this email to 100 your friends - let them see what an idiot you are


More information about the imp mailing list