<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Byung Kyu Park&#039;s Personal Website &#187; calmail</title>
	<atom:link href="http://bkpark.com/tag/calmail/feed/" rel="self" type="application/rss+xml" />
	<link>http://bkpark.com</link>
	<description>Everything about Byung Kyu Park</description>
	<lastBuildDate>Tue, 07 Feb 2012 16:59:37 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Yet another CalMail phishing attempt</title>
		<link>http://bkpark.com/2010/02/20/yet-another-calmail-phishing-attempt/</link>
		<comments>http://bkpark.com/2010/02/20/yet-another-calmail-phishing-attempt/#comments</comments>
		<pubDate>Sun, 21 Feb 2010 06:23:18 +0000</pubDate>
		<dc:creator>bkpark</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[calmail]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[phishing]]></category>

		<guid isPermaLink="false">http://bkpark.com/?p=515</guid>
		<description><![CDATA[Still fairly obvious, but it looks like phishers are getting better. Below is the email with full-headers (headers revealing my secret email server setup redacted): Return-path: <span class="mh-email">xxxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=fX7_gdcqtST-0KpRghBpSr9XI4Y_Tuoo3LwMIlfJmO4=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=fX7_gdcqtST-0KpRghBpSr9XI4Y_Tuoo3LwMIlfJmO4=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span> Envelope-to: <span class="mh-email">xxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=Wm5m0_v9EqnOMa3R--MEQJHXh0VdMVkcAeIBAzSL0UY=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=Wm5m0_v9EqnOMa3R--MEQJHXh0VdMVkcAeIBAzSL0UY=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@xxxxxx.xxx</span> Delivery-date: Sat, 20 Feb 2010 21:19:26 -0800 Received: from xxxxxxxx.berkeley.edu ([128.32.xxx.xxx]) by xxxxx.xxxxxxxxxxxx.xxx with esmtps (TLS1.0:RSA_AES_256_CBC_SHA1:32) (Exim 4.69) (envelope-from &#60;<span class="mh-email">xxxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=fX7_gdcqtST-0KpRghBpSr9XI4Y_Tuoo3LwMIlfJmO4=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=fX7_gdcqtST-0KpRghBpSr9XI4Y_Tuoo3LwMIlfJmO4=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>&#62;) id 1Nj4E2-0003HR-Mg for <span class="mh-email">xxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=Wm5m0_v9EqnOMa3R--MEQJHXh0VdMVkcAeIBAzSL0UY=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=Wm5m0_v9EqnOMa3R--MEQJHXh0VdMVkcAeIBAzSL0UY=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@xxxxxx.xxx</span>; Sat, 20 [...]]]></description>
			<content:encoded><![CDATA[<p>Still fairly obvious, but it looks like phishers are getting better. Below is the email with full-headers (headers revealing my secret email server setup redacted):</p>
<pre>
Return-path: <span class="mh-email">xxxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>
Envelope-to: <span class="mh-email">xxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=Cmh-O_mcqcU-BOPxOIMc_UUzu6IhYUQPm6Ud-UFchuY=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=Cmh-O_mcqcU-BOPxOIMc_UUzu6IhYUQPm6Ud-UFchuY=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@xxxxxx.xxx</span>
Delivery-date: Sat, 20 Feb 2010 21:19:26 -0800
Received: from xxxxxxxx.berkeley.edu ([128.32.xxx.xxx])
        by xxxxx.xxxxxxxxxxxx.xxx with esmtps (TLS1.0:RSA_AES_256_CBC_SHA1:32)
        (Exim 4.69)
        (envelope-from &lt;<span class="mh-email">xxxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>&gt;)
        id 1Nj4E2-0003HR-Mg
        for <span class="mh-email">xxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=Cmh-O_mcqcU-BOPxOIMc_UUzu6IhYUQPm6Ud-UFchuY=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=Cmh-O_mcqcU-BOPxOIMc_UUzu6IhYUQPm6Ud-UFchuY=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@xxxxxx.xxx</span>; Sat, 20 Feb 2010 21:19:26 -0800
Received: from xxxxxxx by xxxxxxxx.Berkeley.EDU with local (Exim 4.69)
        (envelope-from &lt;<span class="mh-email">xxxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>&gt;)
        id 1Nj4E2-0004s1-Bl
        for <span class="mh-email">xxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=Cmh-O_mcqcU-BOPxOIMc_UUzu6IhYUQPm6Ud-UFchuY=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=Cmh-O_mcqcU-BOPxOIMc_UUzu6IhYUQPm6Ud-UFchuY=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@xxxxxx.xxx</span>; Sat, 20 Feb 2010 21:19:26 -0800
Received: from cm03fe.ist.berkeley.edu ([169.229.218.144])
        by xxxxxxxxx.Berkeley.EDU with esmtp (Exim 4.69)
        (envelope-from &lt;<span class="mh-email">webm<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=8kVOM8ua-pvpy26zNXEOj4o9qBHX2f2ts1Nre6AkEQQ=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=8kVOM8ua-pvpy26zNXEOj4o9qBHX2f2ts1Nre6AkEQQ=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>&gt;)
        id 1Nj4E2-0004rv-9i
        for <span class="mh-email">xxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=9hInstEEzMyl6a3FvLVaLt5DZGhvMr4XzJr8zlOSaho=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=9hInstEEzMyl6a3FvLVaLt5DZGhvMr4XzJr8zlOSaho=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@xxxxxxxxxxxx.xxx</span>; Sat, 20 Feb 2010 21:19:26 -0800
Received: from cm09be.ist.berkeley.edu ([169.229.218.182])
        by cm03fe.ist.berkeley.edu with esmtps (TLSv1:AES256-SHA:256)
        (Exim 4.69)
        (envelope-from &lt;<span class="mh-email">webm<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=8kVOM8ua-pvpy26zNXEOj4o9qBHX2f2ts1Nre6AkEQQ=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=8kVOM8ua-pvpy26zNXEOj4o9qBHX2f2ts1Nre6AkEQQ=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>&gt;)
        id 1Nj4E1-0005NQ-Cn
        for <span class="mh-email">xxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=9hInstEEzMyl6a3FvLVaLt5DZGhvMr4XzJr8zlOSaho=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=9hInstEEzMyl6a3FvLVaLt5DZGhvMr4XzJr8zlOSaho=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@xxxxxxxxxxxx.xxx</span>; Sat, 20 Feb 2010 21:19:25 -0800
Received: from cyrus by cm09be.ist.berkeley.edu with local (Exim 4.69)
        (envelope-from &lt;<span class="mh-email">webm<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=8kVOM8ua-pvpy26zNXEOj4o9qBHX2f2ts1Nre6AkEQQ=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=8kVOM8ua-pvpy26zNXEOj4o9qBHX2f2ts1Nre6AkEQQ=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>&gt;)
        id 1Nj4E1-0002WX-Ra
        for <span class="mh-email">xxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=9hInstEEzMyl6a3FvLVaLt5DZGhvMr4XzJr8zlOSaho=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=9hInstEEzMyl6a3FvLVaLt5DZGhvMr4XzJr8zlOSaho=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@xxxxxxxxxxxx.xxx</span>; Sat, 20 Feb 2010 21:19:25 -0800
Received: from cm01fe.ist.berkeley.edu (cm01fe.IST.Berkeley.EDU [169.229.218.142])
        by cm09ms.ist.berkeley.edu (Cyrus v2.3.13-CalMail-v2.3) with LMTPA;
        Sat, 20 Feb 2010 21:19:25 -0800
X-Sieve: CMU Sieve 2.3
Received: from persius.rz.uni-potsdam.de ([141.89.68.1])
        by cm01fe.ist.berkeley.edu with esmtp (Exim 4.69)
        (envelope-from &lt;<span class="mh-email">webm<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=8kVOM8ua-pvpy26zNXEOj4o9qBHX2f2ts1Nre6AkEQQ=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=8kVOM8ua-pvpy26zNXEOj4o9qBHX2f2ts1Nre6AkEQQ=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>&gt;)
        id 1Nj4Dy-0007hK-52; Sat, 20 Feb 2010 21:19:24 -0800
Received: from arnim.rz.uni-potsdam.de (arnim.rz.uni-potsdam.de [141.89.68.11])
        by persius.rz.uni-potsdam.de (8.12.11/8.12.11) with ESMTP id o1L50smS001879;
        Sun, 21 Feb 2010 06:00:54 +0100 (CET)
Received: from uni-potsdam.de (localhost.localdomain [127.0.0.1])
        by arnim.rz.uni-potsdam.de (8.13.8/8.13.8) with ESMTP id o1L50qp1025812;
        Sun, 21 Feb 2010 06:00:52 +0100
Received: from 41.138.182.176 ([41.138.182.176]) by webmail.uni-potsdam.de
        (Horde MIME library) with HTTP; Sun, 21 Feb 2010 06:00:52 +0100
Message-ID: &lt;<span class="mh-email">2010<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=qyIqDwBc7N65vKMVQMscN_ksEGgbJ2_FbgM99tnQG7gHV8AypQ9sBhRBzh6IY_aPQmaKmqZHRr3sys56-Ixgsw==' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=qyIqDwBc7N65vKMVQMscN_ksEGgbJ2_FbgM99tnQG7gHV8AypQ9sBhRBzh6IY_aPQmaKmqZHRr3sys56-Ixgsw==', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@webmail.uni-potsdam.de</span>&gt;
Date: Sun, 21 Feb 2010 06:00:52 +0100
From: "Berkeley.edu Web-Administration" &lt;<span class="mh-email">webm<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=8kVOM8ua-pvpy26zNXEOj4o9qBHX2f2ts1Nre6AkEQQ=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=8kVOM8ua-pvpy26zNXEOj4o9qBHX2f2ts1Nre6AkEQQ=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>&gt;
Reply-to: <span class="mh-email">supp<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=g0UERoJSVzHhkMRrmqix4mqOgswGuS8E5WHPgfJFLo4=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=g0UERoJSVzHhkMRrmqix4mqOgswGuS8E5WHPgfJFLo4=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@live.com</span>
To: undisclosed-recipients: ;
Subject: Alert: Update your CalMail  account
MIME-Version: 1.0
Content-Type: text/plain;
        charset=ISO-8859-1;
        DelSp="Yes";
        format="flowed"
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
User-Agent: Internet Messaging Program (IMP) H3 (4.1.6)
X-Virus-Scanned: clamav-milter 0.95.3 at arnim.rz.uni-potsdam.de
X-Virus-Status: Clean
X-j-chkmail-Score: MSGID : 4B80BE06.000 on persius : j-chkmail score : X : 5/50 0
X-Miltered: at persius with ID 4B80BE06.000 by Joe's j-chkmail (http://j-chkmail.ensmp.fr)!
X-Ucb-Scan-Signature: 606d01dea56a423fb13a5c3f55ff5ffa3eae29a5
X-Ucb-Spam: Gauge=IIIIIII, Probability=7%, Report=''
X-Ucb-Notice: This message has been processed by a spam tagging system.
        See http://mailinfo.berkeley.edu/ for more information.

--

Dear CalMail User,

Your email account needs to be upgraded with our new F-Secure® HTK4S
anti-virus/anti-spam 2010 version.
Fill the columns below and click reply to send back or your account will be
suspended temporary from our services.

CalNet ID:
Passphrase:
Phone Number:

Berkeley.edu Web-Administration
Greg Silva

https://calmail.berkeley.edu/

----©2010, University Of California.
</pre>
<p>Note the fairly convincing From: address. A lot of the suspicious routing information will be hidden by most email clients, <em>however</em>, the Reply-to: header (which would route the email to <span class="mh-email">supp<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=g0UERoJSVzHhkMRrmqix4mqOgswGuS8E5WHPgfJFLo4=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=g0UERoJSVzHhkMRrmqix4mqOgswGuS8E5WHPgfJFLo4=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@live.com</span> and which the phishing relies on) <em>should</em> be set to visible by most email clients, which means, yet again, people who pay attention to details shouldn&#8217;t be taken in by this rather amateurish phishing attempt.</p>
<p>Not to mention one should never send passphrases over email&mdash;even if you know the recipient; email is transmitted in clear text between servers and is <em>inherently insecure</em>. </p>
]]></content:encoded>
			<wfw:commentRss>http://bkpark.com/2010/02/20/yet-another-calmail-phishing-attempt/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Calmail leaks IP addresses!</title>
		<link>http://bkpark.com/2009/11/29/calmail-leaks-ip-addresses/</link>
		<comments>http://bkpark.com/2009/11/29/calmail-leaks-ip-addresses/#comments</comments>
		<pubDate>Sun, 29 Nov 2009 09:43:47 +0000</pubDate>
		<dc:creator>bkpark</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[tech]]></category>
		<category><![CDATA[calmail]]></category>
		<category><![CDATA[gmail]]></category>
		<category><![CDATA[ip address]]></category>
		<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://byungkyupark.com/?p=347</guid>
		<description><![CDATA[For regular visitors of my blog from UCB, here&#8217;s an early holiday Christmas present to you: Calmail leaks IP addresses! Here&#8217;s a quick demonstration (I&#8217;ve seen similar headers on emails from friends and colleagues, but I didn&#8217;t want to expose their info; I&#8217;ve redacted some info here as I didn&#8217;t want to expose my &#8230; [...]]]></description>
			<content:encoded><![CDATA[<p>For regular visitors of my blog from UCB, here&#8217;s an early <strike>holiday</strike> Christmas present to you: Calmail leaks IP addresses! Here&#8217;s a quick demonstration (I&#8217;ve seen similar headers on emails from friends and colleagues, but I didn&#8217;t want to expose their info; I&#8217;ve redacted some info here as I didn&#8217;t want to expose my &#8230; secret email server scheme, or my real username for Calmail):</p>
<pre>
Return-path: <span class="mh-email">xxxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=dyDLj35ECYXkCGNyD8Wn7Z4SXacqEPNBRCYEGwbOlAE=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=dyDLj35ECYXkCGNyD8Wn7Z4SXacqEPNBRCYEGwbOlAE=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@visitor3.berkeley.edu</span>
Envelope-to: <span class="mh-email">bkp<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=zscrs5YV0BrJPIqvASyMDTm6MznGNiH4PWSsGVR6w-4=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=zscrs5YV0BrJPIqvASyMDTm6MznGNiH4PWSsGVR6w-4=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@xxxxxx.xxx</span>
Delivery-date: Sun, 29 Nov 2009 01:32:12 -0800
Received: from visitor3.berkeley.edu ([128.32.124.159])
        by helen.byungkyupark.com with esmtps (TLS1.0:RSA_AES_256_CBC_SHA1:32)
        (Exim 4.69)
        (envelope-from <<span class="mh-email">xxxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=dyDLj35ECYXkCGNyD8Wn7Z4SXacqEPNBRCYEGwbOlAE=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=dyDLj35ECYXkCGNyD8Wn7Z4SXacqEPNBRCYEGwbOlAE=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@visitor3.berkeley.edu</span>>)
        id 1NEg8a-0000jX-J7
        for <span class="mh-email">bkp<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=zscrs5YV0BrJPIqvASyMDTm6MznGNiH4PWSsGVR6w-4=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=zscrs5YV0BrJPIqvASyMDTm6MznGNiH4PWSsGVR6w-4=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@xxxxxx.xxx</span>; Sun, 29 Nov 2009 01:32:12 -0800
Received: from xxxxxxx by visitor3.Berkeley.EDU with local (Exim 4.69)
        (envelope-from <<span class="mh-email">xxxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=dyDLj35ECYXkCGNyD8Wn7Z4SXacqEPNBRCYEGwbOlAE=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=dyDLj35ECYXkCGNyD8Wn7Z4SXacqEPNBRCYEGwbOlAE=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@visitor3.berkeley.edu</span>>)
        id 1NEg8a-0001rk-4v
        for <span class="mh-email">bkp<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=zscrs5YV0BrJPIqvASyMDTm6MznGNiH4PWSsGVR6w-4=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=zscrs5YV0BrJPIqvASyMDTm6MznGNiH4PWSsGVR6w-4=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@xxxxxx.xxx</span>; Sun, 29 Nov 2009 01:32:12 -0800
Received: from smtp-out1.berkeley.edu ([128.32.61.106])
        by visitor3.Berkeley.EDU with esmtp (Exim 4.69)
        (envelope-from <<span class="mh-email">xxxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>>)
        id 1NEg8a-0001rW-2q
        for <span class="mh-email">bkp<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=jXl0hewn54aHhNoqbqT8GHWVD3Hq20ZF_0ks3DnwKT0=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=jXl0hewn54aHhNoqbqT8GHWVD3Hq20ZF_0ks3DnwKT0=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@byungkyupark.com</span>; Sun, 29 Nov 2009 01:32:12 -0800
Received: from arsenic.calmail ([192.168.1.2] helo=calmail.berkeley.edu)
        by fe2.calmail with esmtpsa (TLSv1:AES256-SHA:256)
        (Exim 4.69)
        (auth plain:<span class="mh-email">xxxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>)
        (envelope-from <<span class="mh-email">xxxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>>)
        id 1NEg8T-0000qs-8R
        for <span class="mh-email">bkp<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=jXl0hewn54aHhNoqbqT8GHWVD3Hq20ZF_0ks3DnwKT0=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=jXl0hewn54aHhNoqbqT8GHWVD3Hq20ZF_0ks3DnwKT0=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@byungkyupark.com</span>; Sun, 29 Nov 2009 01:32:06 -0800
MIME-Version: 1.0
Received: from visitor3.Berkeley.EDU [128.32.124.159]
        with HTTP/1.1 (POST); Sun, 29 Nov 2009 01:32:05 -0800
Date: Sun, 29 Nov 2009 01:32:05 -0800
From: "Byung Kyu Park, BA" <<span class="mh-email">xxxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>>
To: <span class="mh-email">bkp<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=jXl0hewn54aHhNoqbqT8GHWVD3Hq20ZF_0ks3DnwKT0=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=jXl0hewn54aHhNoqbqT8GHWVD3Hq20ZF_0ks3DnwKT0=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@byungkyupark.com</span>
Subject: This will demonstrate how Calmail leaks IP addresses
Message-ID: <<span class="mh-email">7272<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=PIZb3BZ65wtedD-LBrEO1s6_ddlpl4eURLiWRU9gu9bksB0BbGqHyEQoJjzd3s48' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=PIZb3BZ65wtedD-LBrEO1s6_ddlpl4eURLiWRU9gu9bksB0BbGqHyEQoJjzd3s48', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>>
X-Sender: <span class="mh-email">xxxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>
User-Agent: RoundCube Webmail/0.3-RC1.UCB3
Content-Type: multipart/alternative;
        boundary="=_ad4b95d1d25a334cada12ae4c3335783"

Content-Transfer-Encoding: 8bit
Content-Type: text/plain; charset="UTF-8"

And this email was composed on the RoundCube webmail client.

Andrew
</pre>
<p>You will see that the detailed email header (which most email clients hide, but there is always an option to show full headers) reveals the IP from which I was accessing Calmail&#8217;s webmail interface (no, I&#8217;m not in the lab right now; but I am proxying through one of my servers, because I consider my current IP address a confidential, personal, private information). Similar headers show if you use SMTP protocol or if you use the other webmail.</p>
<p>I am not entirely sure if this is a feature or bug&mdash;embedding IP information in headers will help with legitimate activities of law enforcement authorities, as well as illegitimate (is there any other kind?) squelching of dissenting voices&mdash;so I haven&#8217;t reported it to <span class="mh-email">abu<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=WdX4nZ0t6okDHer_vsLt9SbNbqXWq2EEI392bvkc4iY=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=WdX4nZ0t6okDHer_vsLt9SbNbqXWq2EEI392bvkc4iY=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span> or, I don&#8217;t know, <span class="mh-email">h<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=JzlZGyzrhl1f-vxngDtmvDxa-12AwpOtYWLW3LGae3g=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=JzlZGyzrhl1f-vxngDtmvDxa-12AwpOtYWLW3LGae3g=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>? <span class="mh-email">secu<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=F_ZV3im-1FOCU20DjclP1b88u6z2m8jp5vIEDGzZM3A=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=F_ZV3im-1FOCU20DjclP1b88u6z2m8jp5vIEDGzZM3A=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>?</p>
<p>In any case, now that you know, now you can avoid using Calmail&mdash;if you value your privacy.</p>
<p>Ironically, GMail may be one of the most secure email system to use, as far as privacy goes, because headers from GMail is fairly clean from any private information. Or, I guess if you are like me, you run a computer server at work, on which you run a bunch of things like websites and email servers so whose IP address isn&#8217;t exactly a state secret. You can proxy everything through that server (like I did here) or run your mail clients and what-not on that server.</p>
<p>No matter what you do, just remember: when you send an email through Calmail, you announce to your recipient what your IP address is at that moment. Don&#8217;t send that email if you are not comfortable with that.</p>
]]></content:encoded>
			<wfw:commentRss>http://bkpark.com/2009/11/29/calmail-leaks-ip-addresses/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

