Great Circle Associates Firewalls
(January 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: smap vs. smtpd
From: Bob Beck <beck @ obtuse . com>
Date: Thu, 23 Jan 1997 11:21:09 -0700 (MST)
To: mike @ ptes . com (Mike Bernhardt)
Cc: firewalls @ GreatCircle . COM
In-reply-to: <v02130516af0c3c63ffa4 @ [138 . 112 . 190 . 103]> from "Mike Bernhardt" at Jan 22, 97 12:53:04 pm

> 
> At 7:38 AM 1/22/97, Samuel D. Jones wrote:
> >Can anyone enlighten me on the differences between
> >smap/smapd and smtpd/smtpfwdd?  Which is more secure?
> >
> I'd like to add to this question... I understood that sendmail 8.8.4
> doesn't have the holes that necessitated smap for earlier versions. Is this
> true? If not, why not?
> 
	No. MTA's (like sendmail, etc) are designed with the first
priority to make mail work well. They don't ignore security issues,
but the first priority is that mail works. They are also constantly
adding features that may bring in other problems.  For example, do a
diff --recursive on (take your pick) sendmail or any other MTA (like
qmail's) source tree from the current version to the version from 1 or
two years ago (which is still likely newer than anything you run from
a vendor unless you're running bleeding edge linux or *BSD
distributions).  Examine the diffs and tell me if any bugs were or
were not introduced in the new code. I bet the diffs themselves are
longer than the entire code for smtpd or smap.

	The point of smtpd or smap is not to eliminate mail problems.
quite frankly as long as users can be clueless and gullible (most of
us are) you can't. The point is to run something simple, reviewable,
paranoid, that adheres strictly to the protocol and knows about
most of the *common* attack avenues against daemons (sendmail or
otherwise).

	It's like a condom. It doesn't eliminate the need to use your
head. It doesn't eliminate the need to take reasonable precautions. 
It does reduce the risk.

	-Bob

 


	

	




Follow-Ups:
References:
Indexed By Date Previous: RE: ToolKits for PC
From: Son Tran <sont @ zoomtel . com>
Next: RE: NT 4.0 Bug
From: Todd Graham Lewis <lists @ reflections . mindspring . com>
Indexed By Thread Previous: Re: smap vs. smtpd
From: Todd Graham Lewis <lists @ reflections . mindspring . com>
Next: Re: smap vs. smtpd
From: Adam Shostack <adam @ homeport . org>

Google
 
Search Internet Search www.greatcircle.com