home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!usc!cs.utexas.edu!swrinde!elroy.jpl.nasa.gov!nntp-server.caltech.edu!SOL1.GPS.CALTECH.EDU!CARL
- From: carl@SOL1.GPS.CALTECH.EDU (Carl J Lydick)
- Newsgroups: comp.os.vms
- Subject: Re: Anonymous SMTP
- Date: 19 Dec 1992 12:00:34 GMT
- Organization: HST Wide Field/Planetary Camera
- Lines: 39
- Distribution: world
- Message-ID: <1gv2t2INNlv7@gap.caltech.edu>
- References: <9212171518.AA10066@ucbvax.Berkeley.EDU>,<1992Dec18.111355.1396@galaxy.gov.bc.ca>
- Reply-To: carl@SOL1.GPS.CALTECH.EDU
- NNTP-Posting-Host: sol1.gps.caltech.edu
-
- In article <1992Dec18.111355.1396@galaxy.gov.bc.ca>, ewilts@galaxy.gov.bc.ca (Ed Wilts) writes:
- >In article <9212171518.AA10066@ucbvax.Berkeley.EDU>, CM3BCH11@staffordshire.ac.uk writes:
- >>
- >> Someone may have mentioned this, but the best way of stopping people
- >> accessing port 25 is to recompile telnet with a check in the code
- >> to stop people specifying port 25. Thats what i'd do.
- >
- >When you have PCs and MACs on your network, you'll quickly find out that you're
- >only fooling yourself on this one. For example, I can easily issue a forgery
- >at any time from my Mac without even breathing hard. I just tried it and the
- >only thing that gave me away was the mail header that included my IP address.
- >If I had a MAC or PC Telnet product that allowed me to specify the port #, my
- >forgery would be even easier.
-
- Sounds like you need to upgrade the SMTP software on your VAX. The better
- products will take the name you give in your HELO line and compare it with a
- lookup of the name[s] associated with the IP address from which you're
- connecting. I.e., they'll gladly let you forge the username, but not the host
- name. Of course, you COULD forge enough intermediate headers that it looks
- like the system from which you're committing the forgery was just one of many
- hops the message took.
-
- >I believe it was Ray Kaplan that once brutally explained in a Decus seminar
- >that one of the first things you need to learn is that there are people out
- >there smarter than you are. Hurts the ego doesn't it?
-
- I'm afraid, then, that Ray was also lulling his audience into a false sense of
- security. One of the points that James (the Amazing) Randi (a stage magician)
- makes in his lectures is that the person trying to fool you doesn't have to be
- smarter than you; he just has to have run across something that never occurred
- to you.
- --------------------------------------------------------------------------------
- Carl J Lydick | INTERnet: CARL@SOL1.GPS.CALTECH.EDU | NSI/HEPnet: SOL1::CARL
-
- Disclaimer: Hey, I understand VAXen and VMS. That's what I get paid for. My
- understanding of astronomy is purely at the amateur level (or below). So
- unless what I'm saying is directly related to VAX/VMS, don't hold me or my
- organization responsible for it. If it IS related to VAX/VMS, you can try to
- hold me responsible for it, but my organization had nothing to do with it.
-