RE: SMTP Service in private DMZ OK?

Matthew.van.Eerde_at_hbinc.com
Date: 01/30/04

  • Next message: Michael Cox: "Controlling Admin Access"
    To: sevans@foundation.sdsu.edu, focus-ms@securityfocus.com
    Date: Fri, 30 Jan 2004 12:33:57 -0800
    
    

    > Who is "that user" that you refer to?
    >
    > If your talking about the mail from: address then so what?

    Agreed.

    > If your talking about the rcpt to: address then so what? Would you
    > prefer that the SMTP service reject that address right then and there,
    > making it even easier to find out what a valid address is?

    There are many good reasons to reject invalid RCPT's at the protocol level
    rather than creating an after-the-fact undeliverable report:

    1) saving of bandwidth by not having to receive the DATA phase
    2) saving of virus/spam scanning
    3) The responsibility of reporting the undeliverable to the sender remains
    with the sending MTA, instead of being shifted onto the receiving MTA

    The reasons to accept invalid RCPT's are less convincing and are akin to
    security-by-obscurity

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: Michael Cox: "Controlling Admin Access"

    Relevant Pages

    • Re: Convert.FromBase64String dotnet bug?
      ... GeezerButler wrote: ... "Invalid length for a Base-64 char array."?? ... Yes - it's like saving a file with the word "Hello" in and then opening ...
      (microsoft.public.dotnet.general)
    • Skin file is invalid
      ... I tried opening it and the WMP gives the following error: The skin file is invalid. ... I tried saving it to my hard drive - but the same problem exists. ...
      (microsoft.public.windowsmedia.player)
    • Re: Skin file is invalid
      ... > WMP gives the following error: The skin file is invalid. ... I tried saving it ...
      (microsoft.public.windowsmedia.player)
    • "invalid argument" message when saving photos?
      ... message "Internet Explorer: Invalid argument", whenever I try saving ... photographs. ...
      (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
    • "invalid argument" message?
      ... message "Internet Explorer: Invalid argument", whenever I try saving ... photographs. ...
      (microsoft.public.windowsxp.general)