是否可以在电子邮件中伪造“已收到”字段?

信息安全 电子邮件 电子邮件欺骗
2021-08-18 23:30:02

我最近收到了一些奇怪的电子邮件。电子邮件具有不同的From字段Reply-To它也已To设置为,Undisclosed recipients但这并不重要。

起初我以为它是假的,但后来我读了这篇文章,其中提到该Received字段不能伪造。对于我正在谈论的电子邮件,似乎收到的是正确的:

Received: (wp-smtpd mx.tlen.pl 14490 invoked from network); 2 Oct 2018 07:19:36 +0200
Received: from mx.beniculturali.it ([194.242.241.200])
          (envelope-sender <pm-pie.aglie@beniculturali.it>)
          by mx.tlen.pl (WP-SMTPD) with ECDHE-RSA-AES256-GCM-SHA384 encrypted SMTP
          for <myemail@10g.pl>; 2 Oct 2018 07:19:36 +0200
Received: from sea2.mail.beniculturali.it (localhost.localdomain [127.0.0.1])
    by localhost (Email Security Appliance) with SMTP id 15EE31ECEEA_BB2FFE8B;
    Tue,  2 Oct 2018 05:19:36 +0000 (GMT)
Received: from MB2.mail.beniculturali.it (mb2.mail.beniculturali.it [192.168.123.122])
    (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits))
    (Client CN "email.beniculturali.it", Issuer "Actalis Authentication CA G3" (not verified))
    by sea2.mail.beniculturali.it (Sophos Email Appliance) with ESMTPS id 1C9BD1E9E28_BB2FFE7F;
    Tue,  2 Oct 2018 05:19:35 +0000 (GMT)
Received: from MB2.mail.beniculturali.it (192.168.123.122) by
 MB2.mail.beniculturali.it (192.168.123.122) with Microsoft SMTP Server (TLS)
 id 15.0.1395.4; Tue, 2 Oct 2018 07:19:30 +0200
Received: from ca4.mail.beniculturali.it (192.168.123.144) by
 MB2.mail.beniculturali.it (192.168.123.122) with Microsoft SMTP Server (TLS)
 id 15.0.1395.4 via Frontend Transport; Tue, 2 Oct 2018 07:19:29 +0200
Received: from MDC.mail.beniculturali.it ([192.168.123.171]) by
 ca4.mail.beniculturali.it ([192.168.123.144]) with mapi; Tue, 2 Oct 2018
 07:19:29 +0200

是否有可能以Received某种方式欺骗领域,也许使用先进的技术?

1个回答

可以向邮件中添加任意字段,其中包括Received标题。但是,任何适当的邮件传输服务器都会Received在邮件顶部添加一个新的标头,这意味着,根据确切的递送基础设施,攻击者最多可以完全伪造除最顶层之外的所有Received标头。在您的特定示例中,顶部Received标头似乎是某个内部服务器,下一个Received标头是来自外围邮件服务器的标头,它接受来自外部的邮件。所有其他Received标头都可能是伪造的。

甚至Received服务器在外围添加标头也可能包含虚假信息。它通常包含 SMTP 客户端在EHLOorHELO命令中声明的主机名因此,在您的特定示例中mx.beniculturali.it,攻击者可能会伪造,同时([194.242.241.200])由接收邮件服务器添加以显示邮件是从哪个源 IP 接收的并且无法伪造。