Great Circle Associates Firewalls
(March 1994)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: RE: don't *bother* flaming about mail fakery
From: Chuck Buda <cbuda @ bluejay . creighton . edu>
Date: Mon, 7 Mar 1994 14:09:24 -0500 (CDT)
To: firewalls @ GreatCircle . Com

>You don't need anonymous servers.  Numerous mailers out there still believe
>the hostname you hand it in the HELO.  Until these are fixed, there's little
>to be done about someone seriously intent on forging.

>I sent this straight from ftp.com with a simple script.  The people at 
>Netcom might want to go over their own machines [and it was sendmail 
>8.6.4, yet].

>_H*  [for reference]

_H* is right!  We've got this problem occuring right now.  It seems that
anyone connected to the Internet can get this information.  Our students
got it from other students.

What's worse, some sendmail's have a help option which will help you
through the process of mail spoofing via sendmail.  When I asked
my support center about it, I got a "Only sysadmins would mess with
sendmail!" type response (amongst others!).

I'd try closing the barn doors, but the builder forgot to supply them.

 *-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*
 *                                                               *
 *  Chuck Buda    (AKA "Sancho")          (cbuda @
 creighton .
 edu)  *  
 *  Unix System(s) Administrator                 also            *
 *  Network Operations Manager           ( (cbuda @
 cu (in JAYNet))* 
 *  Creighton University Computer Center                         *
 *  2500 California St.                  Phone: (402) 280-2260   *
 *  Omaha   NE  68178-0002               FAX  : (402) 280-2573   *
 *                                                               *
 *-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*

Indexed By Date Previous: Re: Authentication of e-mail
From: doug @ seas . smu . edu (Doug Davis)
Next: inetd wrappers for Novell and VMS?
From: Ruggiero Angelo <Angelo . Ruggiero @ zh014 . ubs . ubs . ch>
Indexed By Thread Previous: Re: Authentication of e-mail
From: doug @ seas . smu . edu (Doug Davis)
Next: email workgroup for rfc 821/822/1123 modification
From: "Michael Nittmann, Principal Communications Analyst, The Trane Company (608 787 3792)" <NITTMANN @ UWLAX . EDU>

Google
 
Search Internet Search www.greatcircle.com