Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




fulldisclosure logo Full Disclosure mailing list archives

Re: [FD] FD should block attachments
From: Andrew J Caines <A.J.Caines () halplant com>
Date: Fri, 2 Apr 2004 10:54:54 -0500

Michael,

I think FD should change their policy and block all attachments, except
maybe plain text file's.

Since some folks presumably want to be able to send and receive the latest
MS innovations and other attachments, why don't you just block whatever
you don't want to receive? I certainly do.

The increasing trend of solving security problems by throwing out the
baby, bathtub and any bathroom fittings which can be torn off is
disturbing. It's much the same as the prevalence of the "There should be a
law against that!" culture.

This is certainly not to say SMTP is a good choice of file transfer
protocol, or that it's an efficient use of resources.


Perhaps a more friendly solution would be to have a per-user option to
have attachments (some or all types) stripped. I'm not sure it this is
something Mailman can easily do, but since it already has MIME-specific
handling for digest, I can't imagine it being too hard.


-Andrew-
-- 
 _______________________________________________________________________
| -Andrew J. Caines-   Unix Systems Engineer   A.J.Caines () halplant com  |
| "They that can give up essential liberty to obtain a little temporary |
|  safety deserve neither liberty nor safety" - Benjamin Franklin, 1759 |

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]