On Sat, 13 May 2000, Rachel Polanskis wrote:
> On Sat, 13 May 2000, Anthony Rumble wrote:
>
> > > This would likely include:
> > >
> > > 1. A Daemon re-written in 'C' rather then perl. (primarily for security
> > > reasons)
> >
> > It doesn't really need to be.. I have it start like this
> > su -c mail "/usr/sbin/smtp-virus"
> >
> > That way.. it's running as mail..
> >
> > However, it would be nice to make the whole lot run in a "chroot" jail.
>
>
> Use the sendmail restricted shell to do this.
>
> > > 4. MTA Neutral.
> >
> > It kinda is already.. The main difficulty is you need to make the MTA not
> > listen on port 25... as long as you can do that, it's pretty straight
> > forward.. So Qmail is definately a yes.. Dunno about Postfix and others..
>
> Any MTA can run on any port. it's just a command line argument.
> The problem is that most clients are hardcoded to send on port 25.
>
> > Linux Protector
> >
> > Protectix ?
> >
> > Bastard Mail Gateway from hell?
> > BMGH ?
>
> Mail Sentry?
>
>
> BTW, Why does all this need to be done?
> What about global "procmail" recipes?
> That's all we did to prevent the "virus" from getting into
> our network. I think there's a bit of reinventing of the
> old wheel here, when I think about it......
Procmail only protects stuff as it's written to the users mail spools..
Doesn't help if your say forwading mail inside into many different mail
systems.. including things like exchange and lotus notes.
---
Anthony Rumble
LinuxHelp http://www.LinuxHelp.com.au Phone: 0500 500 368
Direct 02-9712-1799 Mobile 0412-955-042 Fax 02-9712-3977
--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text