mirror of
https://github.com/phishingclub/phishingclub.git
synced 2026-10-04 06:26:51 +02:00
fix mail header message-id was leaking hostname
Signed-off-by: RonniSkansing <rskansing@gmail.com>
This commit is contained in:
4 files changed
+48
No files matched your search
@@ -3199,6 +3199,8 @@ func (c *Campaign) sendCampaignMessages(
|
||||
c.Logger.Errorw("failed to set envelope from", "error", err)
|
||||
return errs.Wrap(err)
|
||||
}
|
||||
// message id from the sending domain so the host is not leaked
|
||||
setMessageIDFromAddress(m, email.MailEnvelopeFrom.MustGet().String())
|
||||
// headers
|
||||
err = m.From(email.MailHeaderFrom.MustGet().String())
|
||||
if err != nil {
|
||||
@@ -5598,6 +5600,8 @@ func (c *Campaign) sendSingleEmailSMTP(
|
||||
c.Logger.Errorw("failed to set envelope from", "error", err)
|
||||
return errs.Wrap(err)
|
||||
}
|
||||
// message id from the sending domain so the host is not leaked
|
||||
setMessageIDFromAddress(m, email.MailEnvelopeFrom.MustGet().String())
|
||||
|
||||
// set headers
|
||||
err = m.From(email.MailHeaderFrom.MustGet().String())
|
||||
@@ -6947,6 +6951,8 @@ func (c *Campaign) SendCampaignReport(
|
||||
}
|
||||
return errs.Wrap(err)
|
||||
}
|
||||
// message id from the sending domain so the host is not leaked
|
||||
setMessageIDFromAddress(m, senderEmail.String())
|
||||
if err := m.From(senderEmail.String()); err != nil {
|
||||
if onDemand {
|
||||
return errs.NewCustomError(fmt.Errorf("the report sender email address is invalid: %w", err))
|
||||
|
||||
@@ -576,6 +576,8 @@ func (m *Email) SendTestEmail(
|
||||
m.Logger.Errorw("failed to set envelope from", "error", err)
|
||||
return errs.Wrap(err)
|
||||
}
|
||||
// message id from the sending domain so the host is not leaked
|
||||
setMessageIDFromAddress(msg, email.MailEnvelopeFrom.MustGet().String())
|
||||
// headers
|
||||
err = msg.From(email.MailHeaderFrom.MustGet().String())
|
||||
if err != nil {
|
||||
|
||||
@@ -0,0 +1,38 @@
|
||||
package service
|
||||
|
||||
import (
|
||||
"strings"
|
||||
|
||||
"github.com/google/uuid"
|
||||
"github.com/wneessen/go-mail"
|
||||
)
|
||||
|
||||
// domainFromEmailAddress returns the domain part of an email address.
|
||||
// it returns an empty string when the address has no domain or the domain
|
||||
// does not look like a real domain (no dot).
|
||||
func domainFromEmailAddress(address string) string {
|
||||
at := strings.LastIndex(address, "@")
|
||||
if at < 0 || at == len(address)-1 {
|
||||
return ""
|
||||
}
|
||||
domain := strings.TrimSpace(address[at+1:])
|
||||
// a right side without a dot is not a valid domain and would look wrong
|
||||
// to a receiving mail server, so treat it as unusable
|
||||
if !strings.Contains(domain, ".") {
|
||||
return ""
|
||||
}
|
||||
return domain
|
||||
}
|
||||
|
||||
// setMessageIDFromAddress sets the message "Message-ID" header as uuid@domain,
|
||||
// using the sending domain as the right side, so outgoing mail does not carry
|
||||
// the machine hostname that go-mail would otherwise use by default.
|
||||
// when the address has no usable domain the message keeps whatever Message-ID
|
||||
// go-mail assigns.
|
||||
func setMessageIDFromAddress(m *mail.Msg, address string) {
|
||||
domain := domainFromEmailAddress(address)
|
||||
if domain == "" {
|
||||
return
|
||||
}
|
||||
m.SetMessageIDWithValue(uuid.NewString() + "@" + domain)
|
||||
}
|
||||
@@ -212,6 +212,8 @@ func (s *SMTPConfiguration) SendTestEmail(
|
||||
s.Logger.Errorw("failed to set envelope from", "error", err)
|
||||
return err
|
||||
}
|
||||
// message id from the sending domain so the host is not leaked
|
||||
setMessageIDFromAddress(m, from.String())
|
||||
// headers
|
||||
err = m.From(from.String())
|
||||
if err != nil {
|
||||
|
||||
Reference in new issue
Block a user