[Esd-l] FW: [Full-Disclosure] Bypassing SMTP Content Protection with a Flick of a Button

Murray Crane mcrane at longbridge.com
Thu Sep 12 08:49:01 PDT 2002


John,

On Thu, 12 Sep 2002 11:30:50 -0400, Rick Thompson wrote:

> ...>SNIP<
> Bypassing SMTP Content Protection with a Flick of a Button
> ...>SNIP<

Could the sanitizer be set to block partial messages? Or equally, is
there a way of asking sendmail not to accept partial messages?

Having read the original BugTraq post myself I was thinking it would
be nice to have the sanitizer fire my local standard security
response (modified to indicate we don't play the partial messages 
game) to senders of such messages.


Kind regards

Murray Crane			Tel: +44 (0)20 7208 5858
Network Systems Administrator	Fax: +44 (0)20 7208 5859
Longbridge International Plc		http://www.longbridge.com

=====
If you receive a non-delivery report [NDR] or "bounce" as a result of 
a reply to this message, please forward it to gracechurchstreet at hotmail.com 
(including full Internet headers if at all possible) so that Longbridge 
International IT support staff can diagnose the cause and correct it.

PGP Public Key Fingerprint: D5C2 0387 608B 3283  FFD7 A042 72A5 AB5A



More information about the esd-l mailing list