Re: Moving forward ...

Craig Hughes <[email protected]> Thu, 26 Feb 2004 19:17:08 -0800
Newsgroups gmane.ietf.asrg.filtering
Message-ID <[email protected]>
Basically you don't have to muck with everyone's MX records and SMTP 
routing to intercept the traffic, you just need the wire between the 
SMTP server(s) and the internet to pass by your IDS.  It's a whole heck 
of a lot easier to drop it into your network if you have some hairy 
SMTP setup already in place that you don't want to mess with.  Or you 
have a delegated administration situation where the guy who owns the 
internet connection doesn 't know or care who's operating what kinds of 
SMTP servers on the LAN.  So yes, I guess that's what you're saying 
too.

C

On Feb 26, 2004, at 3:26 PM, David Nicol wrote:

> Craig Hughes wrote:
>
>> But it'd still be nice to have some kind of way for SUPERIDS to 
>> signal to VICTIM (or downstream filters/MUAs/users) that something 
>> had happened.
>>
>> C
>
>
> Besides altering the VERP and throwing in a header line?
>
> The advantage, over simpy having SUPERIDS speak SMTP in both 
> directions,
> of creating this benevolent MITM, is that we no longer have to
> muck with debugging a consent specification language and our users can 
> write
> weak SMTP daemons without endangering the enterprise?