Great Circle Associates Firewalls
(September 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: RE: about sendmail security
From: Chris Brenton <cbrenton @ pccmis . com>
Date: Fri, 5 Sep 1997 13:05:01 -0400
To: "'Ed Forbes'" <ejf @ bbnplanet . com>
Cc: "'firewalls @ greatcircle . com'" <firewalls @ greatcircle . com>

>> Humm. How about a process that not only checks that the source IP 
>> address can be resolved to a valid host, but that it can be resolved 

>> back to a system which also has a valid MX record.
>> 
>> Just a thought...
> 
>Why would it have to resolve to a valid MX record?  MX records are 
only
>required if the mail shouldn't be returned to the sending host.
>
>Just my thoughts,

I was thinking from a security perspective. For example, if I telnet 
port 25 of your mail host and you are checking to insure that my IP 
address has a valid host name, your machine will accept the connection. 
If however, your machine checks to see if I am a valid mail system 
(i.e. MX record check), it would deny the connection.

True this is not bulletproof, but it does add another layer of 
validation checking to make mail spoofing that much more difficult.




Follow-Ups:
Indexed By Date Previous: RE: about sendmail security
From: Chris Briggs <chris @ cougar . alscomp . com>
Next: Re: Special request
From: Doy <doy @ indo-mail . com>
Indexed By Thread Previous: RE: about sendmail security
From: Chris Briggs <chris @ cougar . alscomp . com>
Next: RE: about sendmail security
From: David Lang <dlang @ diginsite . com>

Google
 
Search Internet Search www.greatcircle.com