Great Circle Associates Firewalls
(December 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: toolkit license
From: proff @ suburbia . net
Date: Wed, 11 Dec 1996 00:51:49 +1100 (EST)
To: avalon @ coombs . anu . edu . au (Darren Reed)
Cc: mjr @ mail . clark . net, firewalls @ GreatCircle . COM
In-reply-to: <199612092202 . OAA21770 @ miles . greatcircle . com> from Darren Reed at "Dec 10, 96 09:01:43 am"

> The FWTK has uses even on non-firewall systems.  Take smapd, for example.
> Using that to receieve internet mail instead of sendmail has been enough
> to provide protection from a number of sendmail bugs (be nice if sendmail 8
> 
> Darren

Not really. smap is quite good about letting in all sorts of headers
that do nasty things to sendmail - all it takes is one vulnerable
machine on the network that smap is willing to pass mail onto. In
fact, from my recolection smap doesn't touch anything after the DATA
command. See the obtuse smtpd sendmail wrapper (ftp.obtuse.com) for
a solution to this (smtpd runs chrooted and "sanitises" ALL headers before
passing them onto sendmail).

You can also run qmail for a single machine solution. Qmail has multiple
mutually untrusting co-operating components (under 7 different uid's) and
is generally well thought out and follows the unix paradigm.

-Julian A.


References:
Indexed By Date Previous: Re: OAI - basic firewall hardware sizing question
From: C Matthew Curtin <cmcurtin @ research . megasoft . com>
Next: Re: Pointers to real-word TIS troubles/joys/configs?
From: Frederick M Avolio <avolio @ tis . com>
Indexed By Thread Previous: Re: toolkit license
From: Darren Reed <avalon @ coombs . anu . edu . au>
Next: Re: toolkit license
From: Rick Murphy <rick @ tis . com>

Google
 
Search Internet Search www.greatcircle.com