Great Circle Associates Firewalls
(September 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Secure version of Sendmail
From: mdr @ vodka . sse . att . com
Date: Thu, 14 Sep 1995 11:02:00 -0400 (EDT)
To: peter @ nmti . com (Peter da Silva)
Cc: firewalls @ greatcircle . com
In-reply-to: <9509132257 . AA09837 @ sonic . nmti . com . nmti . com> from "Peter da Silva" at Sep 13, 95 05:57:13 pm

Peter,
> 
> > The point is, you *can't* guarantee that a large, capable, general
> > purpose package is bug free, whether the bugs are security oriented or
> > anything else. So you need something to backstop it, like Type
> > Enforcement or maybe MLS protections.
> 
> Of course a class B operating system is itself a large, capable, general
> purpose package.
> 

True, but the point is that you must break sendmail *and* the backstop
before your intrusion will be successful.  C2 and higher systems will
be auditing sendmail's every move.   If sendmail forks a shell or
begins to access non mail-related files, a properly configured B level
OS can detect that, and shut sendmail down and alert the administrator.  
Also hacking through a MLS or Type Enforcement system is not trivial.  

The same logic applies to the recent syslog problems.  If your OS can
monitor the daemons, it has a chance to detect when they've been
overrun by means of yet another buffer overflow bug.

That is why I am a strong advocate of running firewalls on trusted
servers.

Mark Riggins
Secure Systems Engineering
AT&T Bell Labs



References:
Indexed By Date Previous: Re: Firewall off Mortal Kombat XIV
From: gary flynn <gary @ habanero . jmu . edu>
Next: Re: Secure version of Sendmail
From: James_Dehnert @ optilink . optilink . dsccc . com
Indexed By Thread Previous: Re: Mulitple levels of security (was Secure version of sendmail)
From: peter @ nmti . com (Peter da Silva)
Next: Re: Secure version of Sendmail
From: jgt10 @ amdahl . com (John G. Thompson)

Google
 
Search Internet Search www.greatcircle.com