Brad
The spammer can still reach your server and could do a DoS, correct. But
with that registry hack, he won't be able to use source routing to spoof his
IP address (acting like he is coming from one of yours) to still be able to
relay mail. If he isn't interested in relaying mail, but instead wants to
pummel your server with a few thousand half-open connections, etc... then
you need to take different measures.
That registry hack was to just add additional information on to what Len
Conrad said about people still being able to spam if they are spoofing your
IP address (source routing being one major way of being able to do that).
Wayne
----- Original Message -----
From: "Bond, Brad" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Friday, April 27, 2001 6:54 PM
Subject: RE: [IMail Forum] Possible DoS attack
>Brad
>Relay for addresses *is* the best bet, followed by SMTP AUTH (when it's
>working for folks).
>The only effective way to spoof a TCP session is to use source routing
on
>the packets. You can disable that at the router, or you can tell NT to
not
>allow for Source Routing.
>Key: [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\
>Parameters]
>Value Name: DisableIPSourceRouting
>Data Type: REG_DWORD (DWORD Value)
>Value Data: '0' or '1'
>Very, very few people ever have a need to specify in the IP packet the
path
>the packet should take (network geeks troubleshooting multihomed
>environments are about it). If you disable IP Source routing on the
server,
>your Cisco router fiend will still have source routing available to him
(if
>(s)he isn't paranoid and has already disable source routing).-------->
What exactly does this mean Wayne, he will still have source routing
available. Can they still spoof their way into my mail server? I mean
it seems to me that their should be some kind of protection for this
stuff. And what i think is, you had told me to lock down my server,
that the same guy that was relaying all that mail got a little hot that
i locked him out so he started a Dos Attack.
Please visit http://www.ipswitch.com/support/mailing-lists.html
to be removed from this list.
An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/