Great Circle Associates Firewalls
(June 1994)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: SMTP mail spoofing
From: Luther Garcia <luth @ tiny . sprintlink . net>
Date: Wed, 22 Jun 1994 14:00:03 -0400 (EDT)
To: Bob Snyder <snyderra @ dunx1 . ocs . drexel . edu>
Cc: David Brooks <0001000502 @ mcimail . com>, Firewalls @ GreatCircle . COM
In-reply-to: <199406221446 . KAA04232 @ dunx1 . ocs . drexel . edu>

you might want to look at smapd in fwtk.

Luther S. Garcia			|"How come you like know so much about
US SPRINT				| getting chicks, but then you like
Sprintlink Engineering/Development	| never get any?"
Herndon, VA.				|
luth @
 sprintlink .
 net			|	-Beavis

On Wed, 22 Jun 1994, Bob Snyder wrote:

> >We would like to know if there is a good way to determine is someone is
> >spoofing our mail gateway.  Is there a "secure" smtpd or other software
> >available that will detect/reject connections from someone pretending to
> >be someone else?
> 
> While sendmail 8 supports the ident protocol, you
> 
> a)  need to hope the remote site supports ident, and
> 
> b)  isn't providing bogus information.
> 
> My Macintosh at home has an Ident daemon running on it.  Of course, it
> returns anything I want it to.
> 
> Generally, your mail transport software will put the IP name/address in the
> Received: headers, and you can trace those back, assuming the other sites
> keep logs.
> 
> If you have a need for secure/nonspoofable email, you should probably
> handle this at the application level, using the variety of mail encryption
> programs that can both provide privacy and authentication of the sender,
> like RIPEM, PGP, or PEM (TIS/PEM).
> 
> Bob
> 
> --
> Bob Snyder N2KGO                                     MIME, RIPEM mail accepted
> snyderra @
 dunx1 .
 ocs .
 drexel .
 edu                       finger for RIPEM public key
>          When cryptography is outlawed, bayl bhgynjf jvyy unir cevinpl.
> 
> 
> 


References:
Indexed By Date Previous: Re: Mosaic weaknesses (was: Re: What are the security risk in opening some UDP ports)
From: "Mark E. Allen" <mallen @ connected . com>
Next: Re: SMTP mail spoofing
From: morgan @ engr . uky . edu (Wes Morgan)
Indexed By Thread Previous: Re: SMTP mail spoofing
From: snyderra @ dunx1 . ocs . drexel . edu (Bob Snyder)
Next: Re: SMTP mail spoofing
From: "Michael S. Hines" <MSHINES @ freh-02 . adpc . purdue . edu>

Google
 
Search Internet Search www.greatcircle.com