also @ TechSpot: Iran targeted by Flame malware in 'most complex' cyber-attack yet

TechSpot

End of the road for SMTP?

Discussion in 'General Discussion' started by Julio Franco, Aug 2, 2003.

Thread Status:
Not open for further replies.
  1. Julio Franco TechSpot Editor

    The protocol that has defined e-mail for more than two decades may have a fatal flaw: It trusts you.

    SMTP makes that assumption because it doesn't suspect that you're sending a Trojan horse virus, that you're making fraudulent pleas for money from the relations of deposed African dictators, or that you're hijacking somebody else's computer to send tens of millions of ads for herbal Viagra.

    Read more: CNet News.
  2. Phantasm66 Newcomer, in training

    SMTP is wide open. You can telnet to the SMTP port on a any server that's running it and without a password start to tell it what to do. You can spoof e-mail messages from any source address you like, and with some work you can spoof the originating IP address as well.

    The fact that it is so wide open is, as Julio has pointed out, responsible for a lot of spam on the net. If we got rid of SMTP, things would improve.
  3. Phantasm66 Newcomer, in training

    Same goes for FTP and PAP. These things were invented when the internet was a much smaller and more trustworthy place. If it had remained in the hands of scientists, academics and technicians then it would have been fine. But now the internet is exposed to untrusted parties. Anything that's not secure is rubbish.
Thread Status:
Not open for further replies.