Anonymous Servers - How do I check encrypted message header?

This is Interesting: Free IT Magazines  
Home > Archive > Anonymous Servers > May 2005 > How do I check encrypted message header?





You are viewing an archived Text-only version of the thread. To view this thread in it's original format and/or if you want to reply to this thread please [click here]

Author How do I check encrypted message header?
Anonymous via the Cypherpunks Tonga Remailer

2005-05-01, 5:48 pm

I pointed my reply blocks that has an Encrypt-Subject to a.a.m.
And I don't receive messages with QS.
How do I check encrypted message header?

Thomas J. Boschloo

2005-05-01, 5:48 pm

-----BEGIN PGP SIGNED MESSAGE-----

Anonymous via the Cypherpunks Tonga Remailer wrote:
> I pointed my reply blocks that has an Encrypt-Subject to a.a.m.
> And I don't receive messages with QS.
> How do I check encrypted message header?


You need to type your unencrypted subject somewhere (I do not have the
nym plugin installed myself yet).

It is best to retrieve all messages in AAM, but if that is too many
messages for your connection you could only download the ones with the
right subject.

If might also be the case that your messages never arrive in AAM. If
this is the case you can never check your messages no matter which
phrase you type!!

Thomas
- --
"Nothing is true. Everything is permitted" - W.S. Burroughs, Naked Lunch
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (MingW32)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

iQB5AwUBQnJDIQEP2l8iXKAJAQEJhgMdHARieCkJ
zy/myMmPGkbbjtM6Om6aZdE6
uTCO2tfGy0eJXDkBfm3TZ7nga24Gi1mhAvg8PX4V
uUTARWj2yscAnrPCroYSBTH2
xVylzTuAud5cl5VVjxJ2huKiyC4TgdMW5fDd4Q==

=zcuQ
-----END PGP SIGNATURE-----
A.Melon

2005-05-01, 5:48 pm

Thank you for your reply!
And sorry for my bad English. I'm not an English speaker.

For example, I set Encrypt-Subject and Subject as below

Encrypt-Subject: foobar
Subject: mail for richard

"mail for richard" is encrypted by "foobar"?

I retrieved all messages in AAM with other newsreader, but I
can't check message header. Since I don't know encrypted message
header looks like.
So I can't find out whether my message don't arrive in AAM or QS
don't retrieve my message.

How do I do?

herehere@aussiemail.com.au

2005-05-01, 5:48 pm

A. Melon wrote:
> Thank you for your reply!
> And sorry for my bad English. I'm not an English speaker.
>
> For example, I set Encrypt-Subject and Subject as below
>
> Encrypt-Subject: foobar
> Subject: mail for richard
>
> "mail for richard" is encrypted by "foobar"?
>
> I retrieved all messages in AAM with other newsreader, but I
> can't check message header. Since I don't know encrypted message
> header looks like.
> So I can't find out whether my message don't arrive in AAM or QS
> don't retrieve my message.
>
> How do I do?


When you use Esub with a passphrase of "foobar" and the subject of
"mail for richard" QS will automatically dl and search for any messages
with the subject header "mail for richard". This subject "mail for
richard" is added by your remailers (I believe) and is the identifying
subject for your mail. Your mail's real subject is encrypted with the
Esub.

If QS finds mail with the subject "mail for richard" QS then tries to
decrypt the MD5 Esub encryption with the passpharse "foobar".

If any of the massages with the Esub subject "mail for richard" are
able to be decrypted by QS using your passphrase "foobar" the mail is
for you (more than one person can use the same Esub subject header).

If QS finds your specified Esub header "mail for richard" and QS can
decrypt the Esub encryption using the passpharse "foobar" QS will then
put the message in your inbox which you can then decrypt using QS.
______________________________________

I asked Richard (creator of QS) about a similar issue last week heres
my question and his response:

(Quoted by me)
6. If I use an Esub setting of "esub=shrimpcreole; mail for richard"
will
*only* the mail that is sent with the subject header of "mail for
richard" be
encrypted with esub?

(Quoted by Richard)
Well, _all_ mail coming through the reply block will have the subject
'mail for richard'. The actual message subject will be in the encrypted
packet. The subject itself will be encrypted with the esub password.

(Quoted by me)
7. When I d-load all messages from a.a.m how does QS know which
messages are
for me?


(Quoted by Richard)
Because in QSnews you tell the program what subjects to look for and if
esub is used you include the esub password. That is all that is needed.


Richard
- --
R.Christman

-----BEGIN PGP SIGNATURE-----
Version: N/A

iQA/AwUBQnGahW9kLqln0NMDEQIWfwCfVk76Lgq/ohr8V+yEGO3ynbup7ngAn19N
t/+6AW2yxWv5jwD322M8Pne3
=LIbS
-----END PGP SIGNATURE-----

________________________________________
________


BTW, don't use the Esub passpharse of "foobar"; create your own unique
and random 10-15 character passpharse.

I am not sure but it seems if everyone used the Esub subject of "mail
for richard" (for example) overall anonymity may be increased in a.a.m
as most all message will look the same (in regards to the Esub
headers).

________________________________________
___________

I suggest you subscribe to the QS mailinglist:
http://www.quicksilvermail.net/mailman/listinfo/qslist

That way you can help directly from Richard.

Hope this helps...I'm sure someone more knowledgeable will come by and
help you.

Thomas J. Boschloo

2005-05-01, 5:48 pm

-----BEGIN PGP SIGNED MESSAGE-----

A.Melon wrote:
> Thank you for your reply!
> And sorry for my bad English. I'm not an English speaker.
>
> For example, I set Encrypt-Subject and Subject as below
>
> Encrypt-Subject: foobar
> Subject: mail for richard
>
> "mail for richard" is encrypted by "foobar"?
>
> I retrieved all messages in AAM with other newsreader, but I
> can't check message header. Since I don't know encrypted message
> header looks like.
> So I can't find out whether my message don't arrive in AAM or QS
> don't retrieve my message.
>
> How do I do?


I don't know how to do it in QS, but I can explain how Esub works:
1. The 16 byte MD5 of "mail for richard" is taken
2. This number is encrypted with IDEA to the MD5 of "foobar"
3. A 8 byte random number called an IV is prepended
4. The resulting 24 bytes are hex encoded for e-mail to a 48 byte string

This 48 bytes string, that is different for each message you receive to
AAM, is your so called Encrypted Subject.

Now to decrypt the string in line 2 you need both the password and the
subject again. Your software (QS) decrypts everything in AAM using your
password "foobar" and sees if either random garbage appears (not a
message for you) or if the MD5 of "mail for richard" re-appears.

The QS help file says:
/////
ESUB is a great tool. You should use it. To enable the QSnews plugin to
search for your encrypted subjects, you need only modify the way you
list the subject in the dialog's subject list.

Without esub, the subject is listed like this:

mail for richard

To enable esub for this subject it is listed like this:

esub=foobar; mail for richard

That is all there is to it. Please note, whitespace between the
semi-colon and the first letter of the next word is ignored when
generating the MD5 message digest. The subject is simply 'mail for richard'.
/////

You will need the QSnews plugin to retrieve AAM in QS.

Hope this helps,
Thomas
- --
"Nothing is true. Everything is permitted" - W.S. Burroughs, Naked Lunch
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (MingW32)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

iQB5AwUBQnOIswEP2l8iXKAJAQGOogMfQmVLlB7U
Atilrjo8GwtNA4F2UWIZ9YMx
Qc+wfx1lyHVhe89ktkh5s/ phYsv1Nhk+DjKQhoNP8XHpGw2SgJIMjZ7ER4SI3x
Py
fxKWvOgLkAm4i/Qriwg03uS5FZE2XBH/x3kwhw==
=PLTU
-----END PGP SIGNATURE-----
herehere@aussiemail.com.au

2005-05-01, 5:48 pm


>
> I don't know how to do it in QS, but I can explain how Esub works:
> 1. The 16 byte MD5 of "mail for richard" is taken
> 2. This number is encrypted with IDEA to the MD5 of "foobar"
> 3. A 8 byte random number called an IV is prepended
> 4. The resulting 24 bytes are hex encoded for e-mail to a 48 byte

string
>
> This 48 bytes string, that is different for each message you receive

to
> AAM, is your so called Encrypted Subject.
>
> Now to decrypt the string in line 2 you need both the password and

the
> subject again. Your software (QS) decrypts everything in AAM using

your
> password "foobar" and sees if either random garbage appears (not a
> message for you) or if the MD5 of "mail for richard" re-appears.
>


Thomas,

Thanks for the clairifacation; my explination and understanding of Esub
was a little off.

Thanks alot

Thomas J. Boschloo

2005-05-01, 5:49 pm

-----BEGIN PGP SIGNED MESSAGE-----

herehere@aussiemail.com.au wrote:

> Thomas,
>
> Thanks for the clairifacation; my explination and understanding of Esub
> was a little off.
>
> Thanks alot


It seemed fine to me. The details are a bit hard at first but I posted
the Esub code from the mixmaster 3.0b2 sources yesterday (and I know
ANSI C a little bit) so I just translated the stuff in there.

You probably didn't you that you need an IV for symmetric or
conventional encryption either, don't worry about it, neither did I at
first!

Regards,
Thomas
- --
"Nothing is true. Everything is permitted" - W.S. Burroughs, Naked Lunch
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (MingW32)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

iQB5AwUBQnOfAgEP2l8iXKAJAQHOFAMfZq4xM6xf
PuJC1IAcyzcaC7t8JxtE8/BB
8hMUZsPFlcA62w5YTjso3oK5OR2RJN+tLGXAnk0M
LFMwurjw1B+CK9kav4nGMXOF
013YzAaIsqBCApu28TZ78LLK+P5fYwClds1NbQ==

=u+9N
-----END PGP SIGNATURE-----
Anonymous

2005-05-01, 5:49 pm

On Fri, 29 Apr 2005, Anonymous via the Cypherpunks Tonga Remailer
<nobody@cypherpunks.to> wrote:
>I pointed my reply blocks that has an Encrypt-Subject to a.a.m.
>And I don't receive messages with QS.
>How do I check encrypted message header?


good question, JBN2 has a "test esub" function.. dunno what QS has for
that.



-=-
This message was sent via two or more anonymous remailing services.




Anonymous

2005-05-03, 7:45 am

Thanks Thomas! Thanks herehere!
I made it!

I had configured reply block as below
nymserver -> remailer -> mail2news gateway
since QS help file says "5) Use One Esub Remailer For Greatest
Success".

And I have changed reply blocks sent direct from nymserver to
mail2news gateway.
Then I succeeded in receiving my mail.

Thank you for your help!


-=-
This message was sent via two or more anonymous remailing services.




BiKiKii Admin

2005-05-03, 8:45 pm

-----BEGIN PGP SIGNED MESSAGE-----

On 3 May 2005, Anonymous wrote:
>Thanks Thomas! Thanks herehere!
>I made it!
>
>I had configured reply block as below nymserver -> remailer -> mail2news gateway
>since QS help file says "5) Use One Esub RemailerFor Greatest Success"
>
>
>And I have changed reply blocks sent direct from nymserver to
>mail2news gateway. Then I succeeded in receiving my mail.
>



The following remailers DO NOT support Esub:

amessage, amigo, antani, crimix, cside, lcs, userbeam



Ciao!

BiKiKii

-----BEGIN PGP SIGNATURE-----
Version: N/A

iQEVAwUBQnfQ3PRwi/QFFzi5AQHgKwf/QhMR50sSthJ2Aue+ddSDihvP0I3F26RB
W8r90LUTR+PKIe6XjAClCkerdn0QPzARPMlrwwP+
or08KMXnrRrO9Nj44PSdZbvO
+glS9AuHOjXKwYC8dydJRud11oZUsoFk+2cmaKzi
zLBylelxhz/3r0HSVb1y4leX
6jcXZLtCAkiDUg6rsnBD5zzQx9fKoj/yRl51dunscL9+HNJq3fJU0DeQwm//FIx+
rl5c1Nl0i/NC/7LHDs3nohxt9gWq0ZVzBkdV0zkfuDMEq+s+9E/lUIuvwzOrZXnW
SEw5bkxMTQZ/ULLMpYoAMN/HdhQJXi9Mh9wLqDFRhm1rFzYaK2kxpw==
=+znO
-----END PGP SIGNATURE-----
Fritz Wuehler

2005-05-04, 2:45 am

<Apple2Remailer@bigapple.dynalias.net> wrote:
>good question, JBN2 has a "test esub" function.. dunno what QS

has for
>that.

I tried JBN2, but JBN2 wouldn't start up on my windows system:-(
Anyway thanks for your reply!

Thomas J. Boschloo

2005-05-07, 5:45 pm

-----BEGIN PGP SIGNED MESSAGE-----

Anonymous wrote:
> Thanks Thomas! Thanks herehere!
> I made it!
>
> I had configured reply block as below
> nymserver -> remailer -> mail2news gateway
> since QS help file says "5) Use One Esub Remailer For Greatest
> Success".
>
> And I have changed reply blocks sent direct from nymserver to
> mail2news gateway.
> Then I succeeded in receiving my mail.
>
> Thank you for your help!


I hope you used Encrypt-Key though! Otherwise your PGP Armor would show
your nyms KeyID (I also hope you used cryptreceive)..

/////
+cryptrecv/-cryptrecv
Enable/disable automatic encryption with your nym's public key of
messages received for your alias. Disabling public-key encryption
will reduce your privacy. However, it may also allow you to decode
received mail with client software designed for the older
alpha.c2.org-style pseudonym servers. Note that even when +cryptrecv
is enabled, you still should use shared-key encryption between
remailer hops to prevent your mail from being traced. See the
section on "SECURITY CONSIDERATIONS" below for more details.
/////

It might be wise to use one hop just in case. That way you can be sure
you can use that remailers directives! IIRC not all nym servers are also
cpunk remailer (with Esub), but I am not sure..

Thomas
- --
"Nothing is true. Everything is permitted" - W.S. Burroughs, Naked Lunch
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (MingW32)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

iQB5AwUBQnzLfwEP2l8iXKAJAQFnIQMfWWwroaCJ
XPvkejJ5jSYgaiKatFN2Imkv
PXNCdujGVSeSRw/ eAmMXLNcqsitIlY2wC7616qcvX3lb0+dzT83XIhQ
8sqTFrL1l
YSBqEZTRCnyRbheD2de+JmIc1Z/IHoeHp67jcQ==
=rjzV
-----END PGP SIGNATURE-----
Thomas J. Boschloo

2005-05-07, 5:45 pm

-----BEGIN PGP SIGNED MESSAGE-----

Fritz Wuehler wrote:
> <Apple2Remailer@bigapple.dynalias.net> wrote:
>
>
> has for
>
>
> I tried JBN2, but JBN2 wouldn't start up on my windows system:-(
> Anyway thanks for your reply!


It was written for Windows 9x, are you using XP? And are you using the
version by Panta-Admin? That would perhaps give you a higher success rate..

Thomas
- --
"Nothing is true. Everything is permitted" - W.S. Burroughs, Naked Lunch
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (MingW32)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

iQB5AwUBQnzLxwEP2l8iXKAJAQEXfgMgh5U5RfnY
ZzglrHagyKEXNmn0jChIQdYD
KF20rSIVRoaKVKgwWCWFsALEym1HHcNNXOSgkSGE
CTJRyoqLC7XJGYyN0AZBqQNr
rmdNBfrvv0hnTyjP3UBNmNiyf9lR9Do/n1PT/A==
=ffWU
-----END PGP SIGNATURE-----
Sponsored Links






Free braindumps | Software forum | Database administration forum

Copyright 2003 - 2008 webservertalk.com