Re: Moving forward ...
Craig Hughes <[email protected]> Thu, 26 Feb 2004 19:17:08 -0800
| Newsgroups | gmane.ietf.asrg.filtering |
|---|---|
| Message-ID | <[email protected]> |
Basically you don't have to muck with everyone's MX records and SMTP routing to intercept the traffic, you just need the wire between the SMTP server(s) and the internet to pass by your IDS. It's a whole heck of a lot easier to drop it into your network if you have some hairy SMTP setup already in place that you don't want to mess with. Or you have a delegated administration situation where the guy who owns the internet connection doesn 't know or care who's operating what kinds of SMTP servers on the LAN. So yes, I guess that's what you're saying too. C On Feb 26, 2004, at 3:26 PM, David Nicol wrote: > Craig Hughes wrote: > >> But it'd still be nice to have some kind of way for SUPERIDS to >> signal to VICTIM (or downstream filters/MUAs/users) that something >> had happened. >> >> C > > > Besides altering the VERP and throwing in a header line? > > The advantage, over simpy having SUPERIDS speak SMTP in both > directions, > of creating this benevolent MITM, is that we no longer have to > muck with debugging a consent specification language and our users can > write > weak SMTP daemons without endangering the enterprise?