Great Circle Associates Majordomo-Users
(September 1994)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: X.400 address 'hostile'
From: eric . hammond @ sdrc . com (Eric Hammond)
Date: Tue, 13 Sep 1994 17:42:55 -0500 (EDT)
To: Jared_Rhine @ hmc . edu
Cc: eric . hammond @ heimdall . sdrc . com, welty @ balltown . cma . com, rogerk @ unpc . queernet . org, mhotti @ paju . oulu . fi, majordomo-users @ GreatCircle . COM
In-reply-to: <199409131915.MAA13695@osiris.ac.hmc.edu> from "Jared_Rhine@hmc.edu" at Sep 13, 94 12:15:55 pm

Jared:

> Hogwash.

Disagreed.  (Obviously, or I would not have said what I said.)

> The possibility that a slash in an e-mail address can open a hole is
> entirely MTA-dependent.

Agreed.

> I am positive that my MTA doesn't have the bug;

Accepted for argument's sake.

> Majordomo shouldn't be enforcing policy decisions that I, as system
> manager, disagree with.

What about this is a policy decision?  Do you believe that majordomo
_should_ allow attackers to circumvent normal security procedures on
some systems simply with a mailing list password which is sent in
plaintext over the Internet and is also stored in a file?  I would
find it extremely fascinating to read a policy which demands that a
software package contain an unnecessary security hole.

If you don't have the particular '/' hole in your MTA, then I would
say that it is perfectly acceptable for you or a majordomo
configuration option to remove that particular check from
&valid_addr().  (Note, however, that other checks currently exist
there and more may be added in the future.)

I believe the definition of what a hostile address is could easily
change depending on the system.  However, to entirely disable hostile
address checking simply because an email message contains a password
is an unacceptable practice in a mailing list software package.

The mailing list password exists to protect the mailing lists.  The
hostile address check exists to protect the computer system.  I say
again that these are two very different levels of security.  This is
the entire foundation of my argument, and until you understand this
your counter-arguments will not convince me.

-- 
Eric.Hammond@sdrc.com       513/576-5907
Structural Dynamics Research Corporation
2000 Eastman Drive, Milford OH 45150 USA




Follow-Ups:
References:
Indexed By Date Previous: RE: majordomo under OSF/1, memory fault
From: "Jim Reisert -- Digital Equipment Corporation -- Maynard, MA 13-Sep-1994 1607" <reisert@wrksys.enet.dec.com>
Next: Re: "lists" command broken on my system
From: Elizabeth Lear Newman <eliz@world.std.com>
Indexed By Thread Previous: Re: X.400 address 'hostile'
From: Jared_Rhine@hmc.edu
Next: Re: X.400 address 'hostile'
From: "Roger B.A. Klorese" <rogerk@unpc.queernet.org>

Google
 
Search Internet Search www.greatcircle.com