Great Circle Associates Firewalls
(October 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: SMTP security breach
From: blizzard @ netpart . com
Date: Thu, 24 Oct 1996 18:48:49 -0700
To: Sunny Azah <sazah @ ibu . sj . nec . COM>
Cc: firewalls @ greatcircle . com
References: <19961014172816 . AAA14235 @ HISHAM> <199610152253 . PAA20037 @ vegas . ibu . sj . nec . com>

Sunny Azah wrote:

> If you're concerned about someone taking a free ride on your
> SMTP server, then that's a different issue.  A much better approach
> to address this problem is to have the SMTP server compare
> the mail's destination against the system sending it the mail.
> If the destination is foreign (outside the local network),
> and the source is also foreign, then refuse to accept the message.
> This prevents someone from the outside network from using your
> SMTP server to deliver mail outside your network, and it does
> it in a way which which doesn't break the SMTP protocol.
> This should be an option, since a feature like this will create problems
> for some sites.

Does anyone know of any mail system or firewall that implements this?  I
seem
to remember that Microsoft Exchange server's SMTP gateway allows you to
do
this, which is hilarious considering Microsoft's poor reputation for
security.

--------------------------------------------------------------------------
Phil Trubey                          |          Manufacturers of
NetPartners Internet Solutions, Inc. |               WebSENSE
E-mail: phil @
 netpart .
 com             |      Internet Screening System
Phone:  619-505-3041                 |       http://www.netpart.com/
--------------------------------------------------------------------------


Follow-Ups:
References:
Indexed By Date Previous: Re: Bay routers and Checkpoint software
From: "Dave Elfering" <elfering @ worldnet . att . net>
Next: Re: port 113
From: girsch @ marben . com (Arnaud Girsch)
Indexed By Thread Previous: Re: SMTP security breach
From: sazah @ ibu . sj . nec . com (Sunny Azah)
Next: Re: SMTP security breach
From: blymn @ awadi . com . au (Brett Lymn)

Google
 
Search Internet Search www.greatcircle.com