home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!spool.mu.edu!nigel.msen.com!emory!swrinde!network.ucsd.edu!mvb.saic.com!mx-list
- From: Dan Wing <DWING@UH01.Colorado.EDU>
- Newsgroups: vmsnet.mail.mx
- Subject: SMTP-over-DECnet security
- Message-ID: <01GSW5HVNETE006MJF@VAXF.COLORADO.EDU>
- Date: 29 Dec 1992 15:32:03 -0700 (MST)
- Organization: Mx-List<==>Vmsnet.Mail.Mx Gateway
- X-Gateway-Source-Info: Mailing List
- Lines: 15
-
- In the MX version 3.1 manual, section 3.8.1, "Creating a DECnet Object for
- DECnet-SMTP", it recommends creating a proxy to allow other systems to use
- the username for the SMTP DECnet object on your local node.
-
- Wouldn't this allow a user on the remote system (SYSTEM, or MAILER, or
- whatever is the user on the remote system) to get your system to run FAL and
- have access to your system, or am I missing something? It seems more secure
- to require the remote system use the normal DECnet login method (the NCP
- database supplies the username, password, and the file to execute) -- it
- seems like this then locks the remote user into executing the pre-defined
- .EXE (or .COM, however you set it up) which can then do nothing more than
- deliver mail all over the place.
-
- -Dan Wing, dwing@uh01.colorado.edu or wing_d@ucolmcc.bitnet (DGW11)
- Systems Administrator, University Hospital, Denver
-