Brad
Relay for addresses *is* the best bet, followed by SMTP AUTH (when it's
working for folks).
The only effective way to spoof a TCP session is to use source routing on
the packets. You can disable that at the router, or you can tell NT to not
allow for Source Routing.
Key: [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\
Parameters]
Value Name: DisableIPSourceRouting
Data Type: REG_DWORD (DWORD Value)
Value Data: '0' or '1'
Very, very few people ever have a need to specify in the IP packet the path
the packet should take (network geeks troubleshooting multihomed
environments are about it). If you disable IP Source routing on the server,
your Cisco router fiend will still have source routing available to him (if
(s)he isn't paranoid and has already disable source routing).
***********************************
Wayne Smith, CNE/MCSE/CCNP/CCDP
Computer Resources (http://www.cros.net)
----- Original Message -----
From: "Bond, Brad" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Friday, April 27, 2001 10:46 AM
Subject: RE: [IMail Forum] Possible DoS attack
Is there something better to use than relay for addresses to stop this?
<< snip >>>
if an attacker is spoofing your ip addresses, the relay for addresses is
useless.
look in you log file, you�ll need decent editor to look a biggish log
file.
Len
Please visit http://www.ipswitch.com/support/mailing-lists.html
to be removed from this list.
An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/