Great Circle Associates Firewalls
(September 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: smap alternative?
From: Dave Roberts <djr @ saa-cons . co . uk>
Date: Thu, 12 Sep 1996 12:57:04 +0100 (BST)
To: Bernd Eckenfels <lists @ lina . inka . de>
Cc: Firewalls Mailing List <firewalls @ greatcircle . com>
In-reply-to: <m0uz4Pc-0004jQC @ lina>

On Fri, 6 Sep 1996, Bernd Eckenfels wrote:

> just use a secure MTA like qmail. If you take a close look at smap you will
> see that it realy doesnt do very much at all.

Sounds good to me.  Sounds exactly like the kind of philosophy that
firewall tools should adhere to.

> It is not very restrictive on
> the addresses and passes a lot of insane data... I dont think it is much
> protection.

I don't agree.  It prevents an external user connecting to a process that
has the run of the system, and often with root privaledges.  smap is a
nice simple process running without root.  It's dumb yes - but that's its
strength.  Reads the mail, drops it into a file, and that's all.  Sounds
perfect.  The address parsing etc can be taken care of later by sendmail,
after smapd has passed the mail onto it.

Dave Roberts        | "Surfing the Internet" is a sad term for sad people.
Unix Systems Admin  | Get a board, find a beach, surf some REAL waves and
SAA Consultants Ltd | get a *real* life.
Plymouth, U.K.      | -=[For PGP Key, send mail with subject of "get pgp"]=-




Follow-Ups:
References:
Indexed By Date Previous: Re: SQL through firewall
From: pauck @ rs3 . wmd . de (Marco Pauck)
Next: Re: SYN floods
From: "Simon J. Gerraty" <sjg @ zen . quick . com . au>
Indexed By Thread Previous: Re: smap alternative?
From: C Matthew Curtin <cmcurtin @ research . megasoft . com>
Next: Re: smap alternative?
From: lists @ lina . inka . de (Bernd Eckenfels)

Google
 
Search Internet Search www.greatcircle.com