Great Circle Associates Firewalls
(April 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Stopping Fakemail (smtpd-port25)
From: "Rick Murphy" <rick @ trusted . com>
Date: Sun, 21 Apr 1996 22:03:32 EDT
To: mulligaj <mulligaj @ lafvax . lafayette . edu>
Cc: firewalls @ greatcircle . com
In-reply-to: Your message of "Sun, 21 Apr 1996 13:32:06 EDT." <2 . 2 . 32 . 19960421173206 . 869706e8 @ lafvax . lafayette . edu>

>Shutting down telnetd is a good idea.  This was considered.  Unfortunatly,
>we do not have a dedicated mailhost.  Instead we have three main machines
>(one VAX and two suns) that must remain open to telnet (port 23).  They key
>would be able to shut down telnet to 25 and allow telnet to 23.  (This is
>sounding like a key firewall question to me. If it is possible, please tell
>me!)  

You can't shut off `telnet' access to port 25 without shutting off ALL
access to port 25. Other than the bit of telnet that negotiates terminal
options and a few other random bits, telnet is a simple character stream
protocol - many TCP/IP protocols are built on an character stream connection.

A firewall *can* be used to limit what hosts can deliver mail to your mail
hub - you can disallow student workstations, for example - but that means
that you've just moved the problem around; a prankster will simply use
one of the systems that are approved for mail access to deliver the mail.
If you try the next obvious approach - building a telnet client on those
systems that doesn't support specification of a port number - they'll just
build their own telnet client from source.

Moral of the story: you can't fix a people problem with technology.  You
can only fix problems like this by making a policy decision - if you catch
people doing this they lose computer access, for example - then publicizing
the policy. Enforce it a few times and the fun is gone.
	-Rick


References:
Indexed By Date Previous: Re: digital unix firewall
From: Shouhei Ando <shouhe-a @ ascii . co . jp>
Next: Re: Firewalls-Digest V5 #147 -Reply (fwd)
From: jallen @ freenet . vcu . edu (John R. Allen)
Indexed By Thread Previous: RE: Stopping Fakemail (smtpd-port25)
From: mulligaj <mulligaj @ lafvax . lafayette . edu>
Next: RE: Stopping Fakemail (smtpd-port25)
From: Michael Dillon <michael @ memra . com>

Google
 
Search Internet Search www.greatcircle.com