Re: a DoS vulnerability associated with conflated Message-IDs?
authorDaniel Kahn Gillmor <dkg@fifthhorseman.net>
Thu, 8 Mar 2012 17:16:18 +0000 (12:16 +1900)
committerW. Trevor King <wking@tremily.us>
Fri, 7 Nov 2014 17:45:19 +0000 (09:45 -0800)
ea/c6fb5e81e79d67c640831090b4fd96e16356f7 [new file with mode: 0644]

diff --git a/ea/c6fb5e81e79d67c640831090b4fd96e16356f7 b/ea/c6fb5e81e79d67c640831090b4fd96e16356f7
new file mode 100644 (file)
index 0000000..b7ce344
--- /dev/null
@@ -0,0 +1,77 @@
+Return-Path: <dkg@fifthhorseman.net>\r
+X-Original-To: notmuch@notmuchmail.org\r
+Delivered-To: notmuch@notmuchmail.org\r
+Received: from localhost (localhost [127.0.0.1])\r
+       by olra.theworths.org (Postfix) with ESMTP id 5C9B8431FB6\r
+       for <notmuch@notmuchmail.org>; Thu,  8 Mar 2012 09:16:22 -0800 (PST)\r
+X-Virus-Scanned: Debian amavisd-new at olra.theworths.org\r
+X-Spam-Flag: NO\r
+X-Spam-Score: 0\r
+X-Spam-Level: \r
+X-Spam-Status: No, score=0 tagged_above=-999 required=5 tests=[none]\r
+       autolearn=disabled\r
+Received: from olra.theworths.org ([127.0.0.1])\r
+       by localhost (olra.theworths.org [127.0.0.1]) (amavisd-new, port 10024)\r
+       with ESMTP id l68mOR6wLNd6 for <notmuch@notmuchmail.org>;\r
+       Thu,  8 Mar 2012 09:16:21 -0800 (PST)\r
+Received: from che.mayfirst.org (che.mayfirst.org [209.234.253.108])\r
+       by olra.theworths.org (Postfix) with ESMTP id CAD03431FAE\r
+       for <notmuch@notmuchmail.org>; Thu,  8 Mar 2012 09:16:21 -0800 (PST)\r
+Received: from [192.168.13.75] (lair.fifthhorseman.net [108.58.6.98])\r
+       by che.mayfirst.org (Postfix) with ESMTPSA id F005BF970;\r
+       Thu,  8 Mar 2012 12:16:17 -0500 (EST)\r
+Message-ID: <4F58E962.1050403@fifthhorseman.net>\r
+Date: Thu, 08 Mar 2012 12:16:18 -0500\r
+From: Daniel Kahn Gillmor <dkg@fifthhorseman.net>\r
+User-Agent: Mozilla/5.0 (X11; Linux i686; rv:9.0) Gecko/20120125 Icedove/9.0.1\r
+MIME-Version: 1.0\r
+To: James Vasile <james@hackervisions.org>\r
+Subject: Re: a DoS vulnerability associated with conflated Message-IDs?\r
+References: <87k42vrqve.fsf@pip.fifthhorseman.net>\r
+       <87ipif2fdn.fsf@wyzanski.jamesvasile.com>\r
+In-Reply-To: <87ipif2fdn.fsf@wyzanski.jamesvasile.com>\r
+Content-Type: text/plain; charset=UTF-8; format=flowed\r
+Content-Transfer-Encoding: 7bit\r
+Cc: notmuch mailing list <notmuch@notmuchmail.org>\r
+X-BeenThere: notmuch@notmuchmail.org\r
+X-Mailman-Version: 2.1.13\r
+Precedence: list\r
+Reply-To: notmuch <notmuch@notmuchmail.org>\r
+List-Id: "Use and development of the notmuch mail system."\r
+       <notmuch.notmuchmail.org>\r
+List-Unsubscribe: <http://notmuchmail.org/mailman/options/notmuch>,\r
+       <mailto:notmuch-request@notmuchmail.org?subject=unsubscribe>\r
+List-Archive: <http://notmuchmail.org/pipermail/notmuch>\r
+List-Post: <mailto:notmuch@notmuchmail.org>\r
+List-Help: <mailto:notmuch-request@notmuchmail.org?subject=help>\r
+List-Subscribe: <http://notmuchmail.org/mailman/listinfo/notmuch>,\r
+       <mailto:notmuch-request@notmuchmail.org?subject=subscribe>\r
+X-List-Received-Date: Thu, 08 Mar 2012 17:16:22 -0000\r
+\r
+On 03/08/2012 12:04 PM, James Vasile wrote:\r
+> On Thu, 08 Mar 2012 11:37:09 -0500, Daniel Kahn Gillmor<dkg@fifthhorseman.net>  wrote:\r
+>> Any ideas on how to approach this?\r
+>\r
+> Treat messages with the same ID but different hashes as different?\r
+\r
+Given that a message hash would include all headers, including Received: \r
+and other MTA-added stuff, i think that would remove all relevance of \r
+the Message-ID field. in particular, it seems like we would just be \r
+identifying messages by their digest.\r
+\r
+If you're willing to ignore the headers and just look at a digest of the \r
+body, that still doesn't provide any help for the common (legitimate) \r
+case of a message jointly-delivered to a mailing list and to a specific \r
+(already-subscribed) user.\r
+\r
+That user will get two copies of the message, and since most mailing \r
+lists modify the body of the message (usually by adding a footer section \r
+with mailing list info) their bodies will also have different digests.\r
+\r
+So i don't see how to make this suggestion work without giving up on \r
+Message-IDs as the identifier entirely (and therefore accepting many \r
+more spurious duplicates than users currently need to tolerate).\r
+\r
+Any other suggestions or ideas?\r
+\r
+       --dkg\r