OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: Content filter wants to know sender's IP
From: Andrew Sweger (andyn2h2.com)
Date: Mon Jun 05 2000 - 00:52:42 CDT


On Jun 5, 2000 8:48am, Alexander Nosenko wrote:

> It looks like content inspection via SMTP has some security deficiencies.
> Inspector can't get access to all info MTA has collected already :-(. All it
> knows is message headers (possibly forged). Besides, some evil program on
> localhost (or somewhere else, depending on firewalling) can connect to 10025
> port (or even 10026 port, what a horror ;-) and have a free run, so
> inspector can't trust even it's clients. The pipe mailer is _the secure way_
> and extendable too (thanks for the idea).

Oh, come on. That's what ipchains is for. Or a DMZ in a properly
configured firewall.

-- 
 Andrew Sweger <andyn2h2.com>   |  N2H2, Incorporated
 Systems Architect               |  900 Fourth Avenue, Suite 3400
 Advanced Technologies Division  |  Seattle WA 98164-1059
 v=206.336.2947  f=206.336.1541  |  http://www.n2h2.com/