Full Disclosure mailing list archives
RE: Backdoor not recognized by Kaspersky
From: Nick FitzGerald <nick () virus-l demon co uk>
Date: Thu, 04 Mar 2004 13:50:59 +1300
"Aditya, ALD [Aditya Lalit Deshmukh]" wrote: <<snip>>
how about the smtp server simply rejecting mail from spoofed hosts ? as all the viruses generate spoofed hosts and it is very easy for any smtp server to do a dns lookup on the sending server, if the hostname / ip address do not match reject the message.
Because, no matter how much you may not like it, some of us have to use spoofing. It is a designed in feature -- sure a "weakness" by today's standards, but not as much of a weakness as the fact that the whole Internet as we know it is based on protocols and mechanisms that _assume_ physical security and guaranteed locatability of connected machines and those with administrative authority over them. In fact, those factors were so deeply ingrained in the original design that I doubt anyone involved in spec'ing, designing and implementing what became ARPAnet even thought to ask about such issues. In short, _if_ something was on that network it was _supposed to be there_. Who in their right mind would adopt such a system for "the Information Super-highway" and encourage business to "get on the net" when it was deployed as an open sewer rather than a self-trusting closed network?? Gluing another layer of "machine authentication" into the SMTP protocol won't fix any of the fundamental underlying problems that allow spam and mass-mailed viruses to aggrieve us so... Regards, Nick FitzGerald _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- Re: Backdoor not recognized by Kaspersky, (continued)
- Re: Backdoor not recognized by Kaspersky Valdis . Kletnieks (Mar 04)
- RE: Backdoor not recognized by Kaspersky Aditya, ALD [Aditya Lalit Deshmukh] (Mar 03)
- RE: Backdoor not recognized by Kaspersky Ron DuFresne (Mar 03)
- Re: Backdoor not recognized by Kaspersky Rodrigo Barbosa (Mar 03)
- Re: Backdoor not recognized by Kaspersky Michael Gale (Mar 03)
- Re: Backdoor not recognized by Kaspersky Nick FitzGerald (Mar 03)
- SMTP open relays and RFC (was: Backdoor not recognized by Kaspersky) Martin Mačok (Mar 04)
- Message not available
- Re: Backdoor not recognized by Kaspersky Rodrigo Barbosa (Mar 04)
- RE: Backdoor not recognized by Kaspersky Nick FitzGerald (Mar 03)
- Re: Backdoor not recognized by Kaspersky Alexander MacLennan (Mar 03)
- RE: Backdoor not recognized by Kaspersky Nick FitzGerald (Mar 03)
- SMTP rejecting wrong HELO/EHLO domains will save the world (was: Backdoor in passworded ZIP not recognized by Kaspersky) Martin Mačok (Mar 03)
- Re: Backdoor not recognized by Kaspersky Valdis . Kletnieks (Mar 04)
- Re: Backdoor not recognized by Kaspersky Nick FitzGerald (Mar 03)
- Re: Backdoor not recognized by Kaspersky Cael Abal (Mar 03)
- Re: Backdoor not recognized by Kaspersky Stef (Mar 03)
- Re: Backdoor not recognized by Kaspersky Nick FitzGerald (Mar 03)
- RE: Backdoor not recognized by Kaspersky Nick FitzGerald (Mar 03)