[imp] use X-Forwarded-For: optionally

Matus UHLAR - fantomas uhlar at fantomas.sk
Wed Jan 23 11:50:26 UTC 2008


On 21.01.08 15:21, Matus UHLAR - fantomas wrote:
> when IMP sends a message, it adds Received: header containing address of
> connecting server, or first server in X-Forwarded-For: HTTP header (if it
> exists).
> 
> However if untrusted client sends whatever data in X-Forwarded-For: header,
> the address (e.g. from private IP raqnge) is used. This results into useless
> garbage inserted into mail headers which mey not be found in horde logs
> (horde does not always log the correct IP).
> 
> Is it possible to add option either to ignore the header, or only to trust
> defined set of IP addresses/ranges which would be trusted (followed)?

OK, bug sent, number 6133
-- 
Matus UHLAR - fantomas, uhlar at fantomas.sk ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
You have the right to remain silent. Anything you say will be misquoted,
then used against you. 


More information about the imp mailing list