Re: Bypassing SMTP Content Protection with a Flick of a Button

From: Steven M. Bellovin (smbat_private)
Date: Fri Sep 13 2002 - 20:19:38 PDT

  • Next message: UkR security team™: "Planet Web Software Buffer Overflow"

    It turns out that this isn't new.  I forwarded the note to Ned Freed, 
    one of the authors of RFC 2046.  He showed it to Kristin Hubner, who 
    found the following text from the manual on using PMDF in a firewall
    that she had written in 1996:
    
       Note that when you are using the conversion channel to check message parts
       on the PMDF firewall system, you are likely to want the defragment channel
       keyword on outgoing channels, particularly channels that send to internal
       systems. The MIME format allows for messages to be split into multiple
       pieces, which are normally not reassembled until arrival at the final
       destination system. However, if you want the intermediate PMDF firewall
       system to check the message content, you will want to reassemble the message
       parts on the PMDF firewall system, so that the message content (rather than
       message content fragments) can be checked.
    
    
    
    
    		--Steve Bellovin, http://www.research.att.com/~smb (me)
    		http://www.wilyhacker.com ("Firewalls" book)
    



    This archive was generated by hypermail 2b30 : Tue Sep 17 2002 - 08:46:37 PDT