Full Disclosure mailing list archives
SMTP rejecting wrong HELO/EHLO domains will save the world (was: Backdoor in passworded ZIP not recognized by Kaspersky)
From: Martin Mačok <martin.macok () underground cz>
Date: Wed, 3 Mar 2004 23:58:32 +0100
On Wed, Mar 03, 2004 at 11:36:09PM +0530, Aditya, ALD [Aditya Lalit Deshmukh] wrote:
how about the smtp server simply rejecting mail from spoofed hosts ? as all the viruses generate spoofed hosts and it is very easy for any smtp server to do a dns lookup on the sending server, if the hostname / ip address do not match reject the message.
I guess you are talking about comparing HELO/EHLO domain with reverse/forward DNS record for the IP of the host. (?) Yes, this would definitely stop almost all SPAM/viruses instantly when "turned on". It just have two little problems - it would also definitely stop almost all email messages - and - there would be also no problem for SPAM/viruses to use real domain in EHLO verb tommorow. Martin Mačok _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- RE: Backdoor not recognized by Kaspersky, (continued)
- RE: Backdoor not recognized by Kaspersky Aditya, ALD [Aditya Lalit Deshmukh] (Mar 03)
- RE: Backdoor not recognized by Kaspersky Ron DuFresne (Mar 03)
- Re: Backdoor not recognized by Kaspersky Rodrigo Barbosa (Mar 03)
- Re: Backdoor not recognized by Kaspersky Michael Gale (Mar 03)
- Re: Backdoor not recognized by Kaspersky Nick FitzGerald (Mar 03)
- SMTP open relays and RFC (was: Backdoor not recognized by Kaspersky) Martin Mačok (Mar 04)
- Message not available
- Re: Backdoor not recognized by Kaspersky Rodrigo Barbosa (Mar 04)
- RE: Backdoor not recognized by Kaspersky Nick FitzGerald (Mar 03)
- Re: Backdoor not recognized by Kaspersky Alexander MacLennan (Mar 03)
- RE: Backdoor not recognized by Kaspersky Nick FitzGerald (Mar 03)
- SMTP rejecting wrong HELO/EHLO domains will save the world (was: Backdoor in passworded ZIP not recognized by Kaspersky) Martin Mačok (Mar 03)
- Re: Backdoor not recognized by Kaspersky Valdis . Kletnieks (Mar 04)
- Re: Backdoor not recognized by Kaspersky Nick FitzGerald (Mar 03)
- Re: Backdoor not recognized by Kaspersky Cael Abal (Mar 03)
- Re: Backdoor not recognized by Kaspersky Stef (Mar 03)
- Re: Backdoor not recognized by Kaspersky Nick FitzGerald (Mar 03)
- RE: Backdoor not recognized by Kaspersky Nick FitzGerald (Mar 03)
- RE: Backdoor not recognized by Kaspersky Rob Rosenberger (Mar 03)