From bounce-fwtk-users-303@listserv.nai.com Thu Nov 15 07:08 EST 2001
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id HAA01193
	Thu, 15 Nov 2001 07:08:54 -0500 (EST)
From: "E. Bostanci"<Bo@zv.fh-mannheim.de>
Organization: Fachhochschule Mannheim
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Date: Thu, 15 Nov 2001 13:14:34 +0100
MIME-Version: 1.0
Content-transfer-encoding: 7BIT
Subject: [fwtk-users] smap
Reply-to: "fwtk-users" <fwtk-users@listserv.nai.com>
Message-ID: <LISTMANAGER-303-154-2001.11.15-06.14.16--fwtk-archive#lists.tislabs.com@listserv.nai.com>
Priority: normal
X-mailer: Pegasus Mail for Win32 (v3.12cDE)
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Content-Type: text/plain; charset=US-ASCII
Content-Length: 800
Status: RO

Hello,
I have a question about the patch of rick for smap.
Why do I get the message "551 Recipient must be in the local
domain(s)" though I have written to the netperm-table "smap: hosts
<aa.bb.cc.*>"? "aa.bb.cc.*" is the ip-address of local hosts (with
wildcard). The "smap: domain..."-option is set correctly, too...

Emin Bostanci

______________________________________________________________
             Dipl.-Inform. (FH) Emin Bostanci
                 Fachhochschule Mannheim
          Hochschule fuer Technik u. Gestaltung
                 Tel.:   +49 (0)621/292-6406
______________________________________________________________

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Thu Nov 15 09:25 EST 2001
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id JAA01616
	Thu, 15 Nov 2001 09:25:48 -0500 (EST)
Message-Id: <LISTMANAGER-303-155-2001.11.15-08.31.32--fwtk-archive#lists.tislabs.com@listserv.nai.com>
X-Sender: pdunphy/mailhost.csca.ryerson.ca@Pop3.norton.antivirus
X-Mailer: QUALCOMM Windows Eudora Version 5.1
Date: Thu, 15 Nov 2001 09:39:12 -0500
To: "fwtk-users" <fwtk-users@listserv.nai.com>
From: Paul Dunphy <pdunphy@research.ryerson.ca>
Subject: [fwtk-users] Re: smap
In-Reply-To: <LISTMANAGER-144-154-2001.11.15-06.14.16--pdunphy#research.
 ryerson.ca@listserv.nai.com>
Mime-Version: 1.0
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 1558
Status: RO

Emin,

I had this problem as well after applying Rick's patch. It turns out that 
with the patched code, you must specify your local host(s) as:

smap: localhosts <list of hosts>
(instead of smap: hosts <list of hosts>)

In other words, just replace the word "hosts" with "localhosts" in your 
netperm-table and everything should work fine.

Cheers...
Paul

At 01:14 PM 11/15/2001 +0100, you wrote:
>Hello,
>I have a question about the patch of rick for smap.
>Why do I get the message "551 Recipient must be in the local
>domain(s)" though I have written to the netperm-table "smap: hosts
><aa.bb.cc.*>"? "aa.bb.cc.*" is the ip-address of local hosts (with
>wildcard). The "smap: domain..."-option is set correctly, too...
>
>Emin Bostanci
>
>______________________________________________________________
>              Dipl.-Inform. (FH) Emin Bostanci
>                  Fachhochschule Mannheim
>           Hochschule fuer Technik u. Gestaltung
>                  Tel.:   +49 (0)621/292-6406
>______________________________________________________________
>
>---
>You are currently subscribed to fwtk-users as: pdunphy@research.ryerson.ca
>To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com


---------------------------------------------------------------------
Paul T. Dunphy, P.Eng.
Systems Administrator/Research Engineer
Ryerson University
Toronto, Ontario, CANADA


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Thu Nov 15 10:30 EST 2001
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id KAA01754
	Thu, 15 Nov 2001 10:30:24 -0500 (EST)
From: "E. Bostanci"<Bo@zv.fh-mannheim.de>
Organization: Fachhochschule Mannheim
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Date: Thu, 15 Nov 2001 16:36:17 +0100
MIME-Version: 1.0
Content-transfer-encoding: 7BIT
Subject: [fwtk-users] Re: smap
Reply-to: "fwtk-users" <fwtk-users@listserv.nai.com>
Message-ID: <LISTMANAGER-303-156-2001.11.15-09.35.58--fwtk-archive#lists.tislabs.com@listserv.nai.com>
Priority: normal
In-reply-to: <LISTMANAGER-749-155-2001.11.15-08.31.32--Bo#zv.fh-mannheim.de@listserv.nai.com>
X-mailer: Pegasus Mail for Win32 (v3.12cDE)
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Content-Type: text/plain; charset=US-ASCII
Content-Length: 2161
Status: RO

Thank you, Paul!! It works really fine now :) 

Emin


> Emin,
> 
> I had this problem as well after applying Rick's patch. It turns out
> that with the patched code, you must specify your local host(s) as:
> 
> smap: localhosts <list of hosts>
> (instead of smap: hosts <list of hosts>)
> 
> In other words, just replace the word "hosts" with "localhosts" in
> your netperm-table and everything should work fine.
> 
> Cheers...
> Paul
> 
> At 01:14 PM 11/15/2001 +0100, you wrote:
> >Hello,
> >I have a question about the patch of rick for smap.
> >Why do I get the message "551 Recipient must be in the local
> >domain(s)" though I have written to the netperm-table "smap: hosts
> ><aa.bb.cc.*>"? "aa.bb.cc.*" is the ip-address of local hosts (with
> >wildcard). The "smap: domain..."-option is set correctly, too...
> >
> >Emin Bostanci
> >
> >______________________________________________________________
> >              Dipl.-Inform. (FH) Emin Bostanci
> >                  Fachhochschule Mannheim
> >           Hochschule fuer Technik u. Gestaltung
> >                  Tel.:   +49 (0)621/292-6406
> >______________________________________________________________
> >
> >---
> >You are currently subscribed to fwtk-users as:
> >pdunphy@research.ryerson.ca To unsubscribe send a blank email to
> >leave-fwtk-users-303A@listserv.nai.com
> 
> 
> ---------------------------------------------------------------------
> Paul T. Dunphy, P.Eng. Systems Administrator/Research Engineer Ryerson
> University Toronto, Ontario, CANADA
> 
> 
> ---
> You are currently subscribed to fwtk-users as: Bo@zv.fh-mannheim.de To
> unsubscribe send a blank email to
> leave-fwtk-users-303A@listserv.nai.com


______________________________________________________________
             Dipl.-Inform. (FH) Emin Bostanci
                 Fachhochschule Mannheim
          Hochschule fuer Technik u. Gestaltung
                 Tel.:   +49 (0)621/292-6406
______________________________________________________________

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Fri Nov 16 09:51 EST 2001
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id JAA03845
	Fri, 16 Nov 2001 09:51:08 -0500 (EST)
X-Authentication-Warning: spider.usrconsult.be: mail set sender to <mbardiaux@peaktime.be> using -f
Message-ID: <LISTMANAGER-303-157-2001.11.16-08.56.31--fwtk-archive#lists.tislabs.com@listserv.nai.com>
Date: Fri, 16 Nov 2001 15:59:24 +0100
From: Michel Bardiaux <mbardiaux@peaktime.be>
Organization: Peaktime Belgium S.A.
X-Mailer: Mozilla 4.73 [en] (WinNT; I)
X-Accept-Language: en,fr
MIME-Version: 1.0
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Bug in ftp-gw.c/sendsaved ?
Content-Transfer-Encoding: 7bit
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain; charset=us-ascii
Content-Length: 2385
Status: RO

Symptoms: FTP client (any) comes from behind a Checkpoint Firewall-1,
goes through TIS FWTK 2.1 ftp-gw (configured incoming), to *any* ftp
server, whather loval or in the DMZ. Client sends "USER foo", receives
"331 Password required for ..." then "421 Service not available".

We looked in the FAQs, the FWTK archives, Google, the FWTK patches
pages, etc... and found about the port-20 problem and patch (which was
already applied), and about the problem of \r\n in a separate packet
from the PORT command, which supposed to be fixed in 2.1.

We then added lots of trace printouts in ftp-gw.c and it finally emerged
that there is one place where the \r\n problem is *not* completely fixed
because there is one case when ftp-gw tals to the client not using
sayn() but directly calling net_send(): in sendsaved(). After patching
sendsaved() the sessions through FW-1 worked.

With the benefit of hindsight, I could find in the archive on reference
to apparently the same problem and the same solution, but the specifics
were not given:

=========== From the archive:

At 11:10 AM 9/8/00 -0500, Larry D. Bonham wrote:
>Rick,
>
>Thanks for the response.  We had already had the default port setting at
>port 20.  We dealt with that problem quite some time ago.

Rats. Never anything easy.


>As it turns out I had to do a little slash and burn.  I disabled most of
>the entire sendsaved() function and sent it directly to flushsaved().  For
>whatever reason the Checkpoint proxy couldn't (wouldn't) handle the
>multiline response 331-.

That's probably a side effect of Checkpoint's "patch" to fix their FTP
vulnerability. That's the only time ftp-gw adds anything to the
interaction, so your change shouldn't have any effect (authenticated ftp
users will probably break, though, if you're using authentication.)
         -Rick

=========== End archive

Now, I unsubscribe from the list during my holidays, I could have missed
the patch when published. If it is a new one, I will post it here, and
someone could put in th the patches web page.

BTW: this patch is already known for Gauntlet.

Greetings,
-- 
Michel Bardiaux
Peaktime Belgium S.A.  Rue Margot, 37  B-1457 Nil St Vincent
Tel : +32 10 65.44.15  Fax : +32 10 65.44.10

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Sat Nov 24 13:35 EST 2001
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id NAA22740
	Sat, 24 Nov 2001 13:35:09 -0500 (EST)
Date: Sat, 24 Nov 2001 13:44:03 -0500 (EST)
From: Ted Keller <keller@bfg.com>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Re: Smap Message: peer dropped connection
In-Reply-To: <LISTMANAGER-13-83-2001.10.23-21.24.35--keller#bfg.com@listserv.nai.com>
Message-ID: <LISTMANAGER-303-204-2001.11.24-12.40.57--fwtk-archive#lists.tislabs.com@listserv.nai.com>
MIME-Version: 1.0
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1112
Status: RO

Rick,

Finally started to analyze your patch.  You are right, our smap versions
have diverged significantly.

In looking at the verify-reverse functionality, it appear that you only
look for a valid dns entry - not that it came from the actual domain on
the from address.  Am I reading this correctly?  Do you see any need to
verify that it actually came from hotmail?  - ie - match the from domain
with the actual host domain?

Appreciate you comments.

ted keller


>
> First, "verify-reverse". Any "from" address that has a domain that matches
> one of these entries must be sent from a host with a reverse DNS matching
> that entry.
> For example, I have:
> smap:   verify-reverse msn.com yahoo.com hotmail.com aol.com lycos.com
> That means that anyone trying to send with "mail from: <foo@hotmail.com>"
> must be sent from a host that's in the hotmail.com domain. This is a real
> spamkiller - 75% of the junk mail I get forges hotmail or yahoo.


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Mon Nov 26 05:46 EST 2001
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id FAA27823
	Mon, 26 Nov 2001 05:46:34 -0500 (EST)
From: "Mathias Haas" <mathias.haas@ue.sr.se>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Connecting to a W2kl-ftp server
Date: Mon, 26 Nov 2001 11:56:06 +0100
Message-ID: <LISTMANAGER-303-213-2001.11.26-04.51.47--fwtk-archive#lists.tislabs.com@listserv.nai.com>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 1366
Status: RO

Hello!

I've got a problem connecting to a Windows 2000 server through FWTK.

Windows 2000 servers that are part of a domain but not a domaincontroller
itself need a Domainname before the username when you connect through FTP
(like: DOMAINNAME\USERNAME). Otherwise W2k doesn't know if the username is
from the local userdatabase or if it is a domain user account.

The problem is that FWTK doesn't seem to accept account names with a
backslash in it. Instead it translates the username as DOMAINNAMEUSERNAME,
i.e. instead of michael\ourdomain you get michaelourdomain.

We wanted to use FWTK in order for our users to update our website. And
instead of having 2000 IP-addresses through the firewall to the DMZ, we
would have only one. We also need domain-users for authentication so that we
can control who gets to do what. The easy solution would be to let the
FTP-server be a domaincontroller, but we've "heard" that when you make a
Windows 2000 server a domaincontroller, it gets very slow since it turns off
a lot of caching.

So I'm turning you guys for help : Is there any way to connect through FWTK
with a "DOMAINNAME\USERNAME" account?

Kind regards,
Mathias Haas
Swedish Broadcasting Corporation


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Mon Nov 26 09:05 EST 2001
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id JAA28388
	Mon, 26 Nov 2001 09:05:26 -0500 (EST)
Date: Mon, 26 Nov 2001 09:14:35 -0500 (EST)
From: Ted Keller <keller@bfg.com>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Re: Connecting to a W2kl-ftp server
In-Reply-To: <LISTMANAGER-13-213-2001.11.26-04.51.47--keller#bfg.com@listserv.nai.com>
Message-ID: <LISTMANAGER-303-214-2001.11.26-08.11.30--fwtk-archive#lists.tislabs.com@listserv.nai.com>
MIME-Version: 1.0
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1994
Status: RO

Mathias,

Just took a quick look through the code.  I didn't see any filtering
preformed on the username/password lines.  May have missed something
here...

I trust that y ou attempted to ftp to your server outside of the fwtk? and
it worked?  You may want to capture that traffic - then compare it to the
traffic from the ftp-gw session and see how the results differ.

ted keller


On Mon, 26 Nov 2001, Mathias Haas wrote:

> Hello!
>
> I've got a problem connecting to a Windows 2000 server through FWTK.
>
> Windows 2000 servers that are part of a domain but not a domaincontroller
> itself need a Domainname before the username when you connect through FTP
> (like: DOMAINNAME\USERNAME). Otherwise W2k doesn't know if the username is
> from the local userdatabase or if it is a domain user account.
>
> The problem is that FWTK doesn't seem to accept account names with a
> backslash in it. Instead it translates the username as DOMAINNAMEUSERNAME,
> i.e. instead of michael\ourdomain you get michaelourdomain.
>
> We wanted to use FWTK in order for our users to update our website. And
> instead of having 2000 IP-addresses through the firewall to the DMZ, we
> would have only one. We also need domain-users for authentication so that we
> can control who gets to do what. The easy solution would be to let the
> FTP-server be a domaincontroller, but we've "heard" that when you make a
> Windows 2000 server a domaincontroller, it gets very slow since it turns off
> a lot of caching.
>
> So I'm turning you guys for help : Is there any way to connect through FWTK
> with a "DOMAINNAME\USERNAME" account?
>
> Kind regards,
> Mathias Haas
> Swedish Broadcasting Corporation
>
>
> ---
> You are currently subscribed to fwtk-users as: keller@bfg.com
> To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com
>


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Mon Nov 26 09:44 EST 2001
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id JAA28503
	Mon, 26 Nov 2001 09:44:14 -0500 (EST)
From: "Mathias Haas" <mathias.haas@ue.sr.se>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] SV: Re: Connecting to a W2kl-ftp server
Date: Mon, 26 Nov 2001 15:53:48 +0100
Message-ID: <LISTMANAGER-303-215-2001.11.26-08.49.17--fwtk-archive#lists.tislabs.com@listserv.nai.com>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
Importance: Normal
In-Reply-To: <LISTMANAGER-730-214-2001.11.26-08.11.30--mathias.haas#ue.sr.se@listserv.nai.com>
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain;
	charset="US-ASCII"
Content-Length: 3306
Status: RO

Hello Ted! Thank for the reply!

Well, the reason I thought FWTK filters out the backslash is because it
looks like this:

220 Hello! Welcome to the FTP-Proxy!
User (134.25.115.28:(none)): INTERNET\uematha@www.sr.se
331-(----GATEWAY CONNECTED TO www.sr.se----)
331-(220 www Microsoft FTP Service (Version 5.0).)
331 Password required for INTERNETuematha.
Password:
530 User INTERNETuematha cannot log in.
Login failed.
ftp>

Or simliar:

C:\>ftp 134.25.115.28
Connected to 134.25.115.28.
220 Hej! Valkommen till FTP-Proxyn!
User (134.25.115.28:(none)): !"#$%&/()=??$?{[]}\@www.sr.se
331-(----GATEWAY CONNECTED TO www.sr.se----)
331-(220 www Microsoft FTP Service (Version 5.0).)
331 Password required for !#%&/()=?$?{[]}.
Password:
530 User !#%&/()=?$?{[]} cannot log in.
Login failed.
ftp>

The characters !"#$%&/()=?` are shift + 1234567890+
And the @?$?{[]}\ are Alt + 1234567890+

It seems that certain high-ascii chars are filtered out, or what do you
think?

/mathias


-----Ursprungligt meddelande-----
Fran: Ted Keller [mailto:keller@bfg.com]
Skickat: den 26 november 2001 15:15
Till: fwtk-users
Amne: [fwtk-users] Re: Connecting to a W2kl-ftp server


Mathias,

Just took a quick look through the code.  I didn't see any filtering
preformed on the username/password lines.  May have missed something
here...

I trust that y ou attempted to ftp to your server outside of the fwtk? and
it worked?  You may want to capture that traffic - then compare it to the
traffic from the ftp-gw session and see how the results differ.

ted keller


On Mon, 26 Nov 2001, Mathias Haas wrote:

> Hello!
>
> I've got a problem connecting to a Windows 2000 server through FWTK.
>
> Windows 2000 servers that are part of a domain but not a domaincontroller
> itself need a Domainname before the username when you connect through FTP
> (like: DOMAINNAME\USERNAME). Otherwise W2k doesn't know if the username is
> from the local userdatabase or if it is a domain user account.
>
> The problem is that FWTK doesn't seem to accept account names with a
> backslash in it. Instead it translates the username as DOMAINNAMEUSERNAME,
> i.e. instead of michael\ourdomain you get michaelourdomain.
>
> We wanted to use FWTK in order for our users to update our website. And
> instead of having 2000 IP-addresses through the firewall to the DMZ, we
> would have only one. We also need domain-users for authentication so that
we
> can control who gets to do what. The easy solution would be to let the
> FTP-server be a domaincontroller, but we've "heard" that when you make a
> Windows 2000 server a domaincontroller, it gets very slow since it turns
off
> a lot of caching.
>
> So I'm turning you guys for help : Is there any way to connect through
FWTK
> with a "DOMAINNAME\USERNAME" account?
>
> Kind regards,
> Mathias Haas
> Swedish Broadcasting Corporation
>
>
> ---
> You are currently subscribed to fwtk-users as: keller@bfg.com
> To unsubscribe send a blank email to
leave-fwtk-users-303A@listserv.nai.com
>


---
You are currently subscribed to fwtk-users as: mathias.haas@ue.sr.se
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Mon Nov 26 10:28 EST 2001
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id KAA28557
	Mon, 26 Nov 2001 10:28:40 -0500 (EST)
Message-Id: <LISTMANAGER-303-216-2001.11.26-09.33.53--fwtk-archive#lists.tislabs.com@listserv.nai.com>
X-Sender: pdunphy/mailhost.csca.ryerson.ca@Pop3.norton.antivirus
X-Mailer: QUALCOMM Windows Eudora Version 5.1
Date: Mon, 26 Nov 2001 10:42:33 -0500
To: "fwtk-users" <fwtk-users@listserv.nai.com>
From: Paul Dunphy <pdunphy@research.ryerson.ca>
Subject: [fwtk-users] Re: Smap Message: peer dropped connection
In-Reply-To: <LISTMANAGER-144-204-2001.11.24-12.40.57--pdunphy#research.
 ryerson.ca@listserv.nai.com>
Mime-Version: 1.0
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 2508
Status: RO

Ted,

I should probably let Rick answer this, but I'm using his patch and it does 
indeed check that each message that claims to be from one of the domains 
listed in the "verify-reverse" entry is in fact from that domain. Note the 
following code segment, which begins at line 2111 in my (slightly modified) 
smap.c file:

         if (InCheckList(domain,cfp,"verify-reverse")) {
                 /* Must have a valid reverse DNS */
                 if (strcmp(rladdr, "unknown") == 0) {
                         return (FromNoRDNS);
                 }
                 else if (strstr(rladdr, domain) == NULL) {
                         return(FromDNSSpoof);
                 }

The "strstr(rladdr, domain)" statement above checks to see that the domain 
specified in the From address is in fact contained in the "real" domain 
name that was obtained by reverse-DNS lookup, and returns FromDNSSpoof if 
it does not.

Incidentally, I had to modify this code slightly since I have msn.com 
listed in my verify-reverse line, but it seems that valid e-mail from 
msn.com users actually come from a hotmail.com server. Since a lot of 
spammers try to spoof msn.com in their From lines, I didn't want to remove 
msn.com from my verify-reverse list, so I hard-coded an additional check 
for this special case in the code. Maybe one day, in my spare time :), I'll 
create a more elegant solution.

Cheers...
Paul

P.S. Rick, thank you *very much* for this patch -- not only has it solved 
my "peer dropped connection" problem, but I am very happy with the amount 
of spam I am now able to reject. Good work!!

At 01:44 PM 11/24/2001 -0500, you wrote:
>Rick,
>
>Finally started to analyze your patch.  You are right, our smap versions
>have diverged significantly.
>
>In looking at the verify-reverse functionality, it appear that you only
>look for a valid dns entry - not that it came from the actual domain on
>the from address.  Am I reading this correctly?  Do you see any need to
>verify that it actually came from hotmail?  - ie - match the from domain
>with the actual host domain?
>
>Appreciate you comments.
>
>ted keller


---------------------------------------------------------------------
Paul T. Dunphy, P.Eng.
Systems Administrator/Research Engineer
Centre for the Study of Commercial Activity
Ryerson University
Toronto, Ontario, CANADA


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Mon Nov 26 10:55 EST 2001
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id KAA28643
	Mon, 26 Nov 2001 10:55:01 -0500 (EST)
From: ark@eltex.ru
Date: Mon, 26 Nov 2001 18:56:12 +0300
Message-Id: <LISTMANAGER-303-217-2001.11.26-10.00.14--fwtk-archive#lists.tislabs.com@listserv.nai.com>
In-Reply-To: <LISTMANAGER-333-215-2001.11.26-08.49.17--ark#eltex.ru@listserv.nai.com> from ""Mathias Haas" <mathias.haas@ue.sr.se>"
Organization: "Klingon Imperial Intelligence Service"
Subject: [fwtk-users] Re: SV: Re: Connecting to a W2kl-ftp server
To: "fwtk-users" <fwtk-users@listserv.nai.com>
X-Virus-Scanned: by Eltex TC
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text
Content-Length: 1323
Status: RO

-----BEGIN PGP SIGNED MESSAGE-----

What happens if you replace / with // ?

"Mathias Haas" <mathias.haas@ue.sr.se> said :

> Hello Ted! Thank for the reply!
> 
> Well, the reason I thought FWTK filters out the backslash is because it
> looks like this:
> 
> 220 Hello! Welcome to the FTP-Proxy!
> User (134.25.115.28:(none)): INTERNET\uematha@www.sr.se
> 331-(----GATEWAY CONNECTED TO www.sr.se----)
> 331-(220 www Microsoft FTP Service (Version 5.0).)
> 331 Password required for INTERNETuematha.
> Password:
> 530 User INTERNETuematha cannot log in.
> Login failed.
> ftp>
 

                                     _     _  _  _  _      _  _
 {::} {::} {::}  CU in Hell          _| o |_ | | _|| |   / _||_|   |_ |_ |_
 (##) (##) (##)        /Arkan#iD    |_  o  _||_| _||_| /   _|  | o |_||_||_|
 [||] [||] [||]            Do i believe in Bible? Hell,man,i've seen one!

-----BEGIN PGP SIGNATURE-----
Version: PGP 6.5.1i

iQCVAwUBPAJmGKH/mIJW9LeBAQHtLgQAkGShDYnirqWMMLIHFX6PpivyFfuMK/RB
k/yTPciKqHJOTa4gWY5iO8i2aAQN7or6qJUnFTzvn/lXmVO9zMnud9B44J0hSFeM
JIS9I4akAGTRNh1sYgtt96OCfCC/Q1dgHQ2TJF2JdtVFvfoJqEns+23yLGxnvW+C
vlfibBUHyU4=
=JY3T
-----END PGP SIGNATURE-----

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Mon Nov 26 13:39 EST 2001
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id NAA29244
	Mon, 26 Nov 2001 13:39:53 -0500 (EST)
Sender: root@peabody.bath.tmac.com
Message-ID: <LISTMANAGER-303-222-2001.11.26-12.45.16--fwtk-archive#lists.tislabs.com@listserv.nai.com>
Date: Mon, 26 Nov 2001 11:29:47 -0500
From: Steve Sandau <ssandau@bath.tmac.com>
X-Mailer: Mozilla 4.78 [en] (X11; U; Linux 2.2.16 i686)
X-Accept-Language: en
MIME-Version: 1.0
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Re: Connecting to a W2kl-ftp server
Content-Transfer-Encoding: 7bit
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain; charset=us-ascii
Content-Length: 2441
Status: RO

If I were trying to pass that argument to a shell script, I'd double up
the backslash. Might that work here?

Ted Keller wrote:
> 
> Mathias,
> 
> Just took a quick look through the code.  I didn't see any filtering
> preformed on the username/password lines.  May have missed something
> here...
> 
> I trust that y ou attempted to ftp to your server outside of the fwtk? and
> it worked?  You may want to capture that traffic - then compare it to the
> traffic from the ftp-gw session and see how the results differ.
> 
> ted keller
> 
> On Mon, 26 Nov 2001, Mathias Haas wrote:
> 
> > Hello!
> >
> > I've got a problem connecting to a Windows 2000 server through FWTK.
> >
> > Windows 2000 servers that are part of a domain but not a domaincontroller
> > itself need a Domainname before the username when you connect through FTP
> > (like: DOMAINNAME\USERNAME). Otherwise W2k doesn't know if the username is
> > from the local userdatabase or if it is a domain user account.
> >
> > The problem is that FWTK doesn't seem to accept account names with a
> > backslash in it. Instead it translates the username as DOMAINNAMEUSERNAME,
> > i.e. instead of michael\ourdomain you get michaelourdomain.
> >
> > We wanted to use FWTK in order for our users to update our website. And
> > instead of having 2000 IP-addresses through the firewall to the DMZ, we
> > would have only one. We also need domain-users for authentication so that we
> > can control who gets to do what. The easy solution would be to let the
> > FTP-server be a domaincontroller, but we've "heard" that when you make a
> > Windows 2000 server a domaincontroller, it gets very slow since it turns off
> > a lot of caching.
> >
> > So I'm turning you guys for help : Is there any way to connect through FWTK
> > with a "DOMAINNAME\USERNAME" account?
> >
> > Kind regards,
> > Mathias Haas
> > Swedish Broadcasting Corporation
> >
> >
> > ---
> > You are currently subscribed to fwtk-users as: keller@bfg.com
> > To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com
> >
> 
> ---
> You are currently subscribed to fwtk-users as: ssandau@tmac.com
> To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

-- 
Steve Sandau, IS Technician
TMA Bath, Maine
ssandau@bath.tmac.com

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Mon Nov 26 19:45 EST 2001
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id TAA00710
	Mon, 26 Nov 2001 19:45:44 -0500 (EST)
Message-Id: <LISTMANAGER-303-223-2001.11.26-18.50.53--fwtk-archive#lists.tislabs.com@listserv.nai.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.1
Date: Mon, 26 Nov 2001 19:48:49 -0500
To: "fwtk-users" <fwtk-users@listserv.nai.com>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: [fwtk-users] Re: Connecting to a W2kl-ftp server
In-Reply-To: <LISTMANAGER-602-213-2001.11.26-04.51.47--rmurphy#itm-inst.
 com@listserv.nai.com>
Mime-Version: 1.0
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 603
Status: RO

At 11:56 AM 11/26/01 +0100, Mathias Haas wrote:
>The problem is that FWTK doesn't seem to accept account names with a
>backslash in it. Instead it translates the username as DOMAINNAMEUSERNAME,
>i.e. instead of michael\ourdomain you get michaelourdomain.

The command parser that FWTK uses (enargv) "handles" backslashes - it 
treats it like a quote character. If you use two backslashes (\\), a single 
backslash will be sent.
         -Rick


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Mon Nov 26 20:04 EST 2001
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id UAA00748
	Mon, 26 Nov 2001 20:04:50 -0500 (EST)
Message-Id: <LISTMANAGER-303-224-2001.11.26-19.10.53--fwtk-archive#lists.tislabs.com@listserv.nai.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.1
Date: Mon, 26 Nov 2001 20:13:36 -0500
To: "fwtk-users" <fwtk-users@listserv.nai.com>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: [fwtk-users] Re: Smap Message: peer dropped connection
In-Reply-To: <LISTMANAGER-602-216-2001.11.26-09.33.53--rmurphy#itm-inst.
 com@listserv.nai.com>
Mime-Version: 1.0
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 2253
Status: RO

At 10:42 AM 11/26/01 -0500, Paul Dunphy wrote:
>Ted,
>
>I should probably let Rick answer this, but I'm using his patch and it 
>does indeed check that each message that claims to be from one of the 
>domains listed in the "verify-reverse" entry is in fact from that domain. 
>Note the following code segment, which begins at line 2111 in my (slightly 
>modified) smap.c file:
>
>         if (InCheckList(domain,cfp,"verify-reverse")) {
>                 /* Must have a valid reverse DNS */
>                 if (strcmp(rladdr, "unknown") == 0) {
>                         return (FromNoRDNS);
>                 }
>                 else if (strstr(rladdr, domain) == NULL) {
>                         return(FromDNSSpoof);
>                 }
>
>The "strstr(rladdr, domain)" statement above checks to see that the domain 
>specified in the From address is in fact contained in the "real" domain 
>name that was obtained by reverse-DNS lookup, and returns FromDNSSpoof if 
>it does not.

Paul's got it right.

>Incidentally, I had to modify this code slightly since I have msn.com 
>listed in my verify-reverse line, but it seems that valid e-mail from 
>msn.com users actually come from a hotmail.com server. Since a lot of 
>spammers try to spoof msn.com in their From lines, I didn't want to remove 
>msn.com from my verify-reverse list, so I hard-coded an additional check 
>for this special case in the code. Maybe one day, in my spare time :), 
>I'll create a more elegant solution.

A more consistent way to do that would be to allow an optional domain name 
(msn.com:hotmail.com for example); I'd change it to check "msn.com" from 
addresses for reverse domains in "msn.com" or "hotmail.com".

>P.S. Rick, thank you *very much* for this patch -- not only has it solved 
>my "peer dropped connection" problem, but I am very happy with the amount 
>of spam I am now able to reject. Good work!!

I've been very happy with the quantity of junk being rejected this way. 
I've had to add a few whitelist entries since doing this, but it's been 
very effective in spam killing.
         -Rick


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Mon Nov 26 20:27 EST 2001
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id UAA00870
	Mon, 26 Nov 2001 20:27:34 -0500 (EST)
Date: Mon, 26 Nov 2001 20:28:36 -0500
From: Tim Sailer <sailer@bnl.gov>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Radius or PAM auth?
Message-ID: <LISTMANAGER-303-225-2001.11.26-19.32.50--fwtk-archive#lists.tislabs.com@listserv.nai.com>
Mime-Version: 1.0
Content-Disposition: inline
User-Agent: Mutt/1.3.23i
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain; charset=us-ascii
Content-Length: 401
Status: RO

Has anyone looked at supporting external authentication of a generic
kind? PAM would be great, but even RADIUS would do.

Tim

-- 
Tim Sailer <sailer@bnl.gov> 
Manager, Cyber Security Operations
Brookhaven National Laboratory  (631) 344-3001

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Tue Nov 27 12:47 EST 2001
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id MAA03413
	Tue, 27 Nov 2001 12:47:17 -0500 (EST)
Subject: [fwtk-users] Re: Smap Message: peer dropped connection
From: Tony Gale <gale@syntax.dstl.gov.uk>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
In-Reply-To: 
	<LISTMANAGER-280-224-2001.11.26-19.10.53--gale#syntax.dera.gov.uk@listserv.n
	ai.com>
Content-Transfer-Encoding: 7bit
X-Mailer: Evolution/0.99.2 (Preview Release)
Date: 27 Nov 2001 09:38:41 +0000
Message-Id: <LISTMANAGER-303-227-2001.11.27-11.52.36--fwtk-archive#lists.tislabs.com@listserv.nai.com>
Mime-Version: 1.0
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain
Content-Length: 876
Status: RO

On Tue, 2001-11-27 at 01:13, Rick Murphy wrote:
> At 10:42 AM 11/26/01 -0500, Paul Dunphy wrote:
> >Ted,
> >
> >The "strstr(rladdr, domain)" statement above checks to see that the domain 
> >specified in the From address is in fact contained in the "real" domain 
> >name that was obtained by reverse-DNS lookup, and returns FromDNSSpoof if 
> >it does not.
> 
> Paul's got it right.

I haven't looked into the code, but am going from the description above.
I believe the "correct" way to do this check is to look up the MX record
for the envelope senders domain and check it against the address of the
sending system.

Using a reverse dns lookup is much more likely to fail and to give an
incorrect result.

-tony



---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Tue Nov 27 19:31 EST 2001
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id TAA05080
	Tue, 27 Nov 2001 19:31:19 -0500 (EST)
Message-Id: <LISTMANAGER-303-230-2001.11.27-18.36.51--fwtk-archive#lists.tislabs.com@listserv.nai.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.1
Date: Tue, 27 Nov 2001 19:35:59 -0500
To: "fwtk-users" <fwtk-users@listserv.nai.com>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: [fwtk-users] Re: Smap Message: peer dropped connection
In-Reply-To: <1006853921.9923.2.camel@syntax.dstl.gov.uk>
Mime-Version: 1.0
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 1053
Status: RO

At 09:38 AM 11/27/01 +0000, Tony Gale wrote:
>I haven't looked into the code, but am going from the description above.
>I believe the "correct" way to do this check is to look up the MX record
>for the envelope senders domain and check it against the address of the
>sending system.
>
>Using a reverse dns lookup is much more likely to fail and to give an
>incorrect result.

For the big ISPs that is being used on, that's not the case. A big ISP's 
outgoing SMTP servers aren't necessarily the same as their incoming servers 
- but they're very likely to have a valid reverse lookup in their own domain.

All the patch does is to say that if you're trying to send mail with an 
envelope sender of "*@yahoo.com", you *must* be coming from a host with a 
valid reverse DNS somewhere in the yahoo.com domain. So far, that works 
well for detecting the most common forged domains.
         -Rick


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Wed Nov 28 01:59 EST 2001
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id BAA06385
	Wed, 28 Nov 2001 01:59:22 -0500 (EST)
X-Authentication-Warning: guardian.hartwellcorp.com: mail set sender to <mikes@hartwellcorp.com> using -f
Message-ID: <LISTMANAGER-303-231-2001.11.28-01.04.38--fwtk-archive#lists.tislabs.com@listserv.nai.com>
From: "Michael St. Laurent" <mikes@hartwellcorp.com>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] RBL lookups don't work anymore
Date: Tue, 27 Nov 2001 23:08:49 -0800
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 378
Status: RO

Are RBL lookups still working for you folks?  They don't seem to work for me
anymore even if I try them via nslookup.

--------------------
Michael St. Laurent
Hartwell Corporation

[root@earth] root# rm -rf /bin/laden

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Wed Nov 28 04:20 EST 2001
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id EAA06679
	Wed, 28 Nov 2001 04:20:55 -0500 (EST)
From: "Mathias Haas" <mathias.haas@ue.sr.se>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] SV: Re: Connecting to a W2kl-ftp server
Date: Wed, 28 Nov 2001 10:30:26 +0100
Message-ID: <LISTMANAGER-303-232-2001.11.28-03.26.01--fwtk-archive#lists.tislabs.com@listserv.nai.com>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
Importance: Normal
In-Reply-To: <LISTMANAGER-730-223-2001.11.26-18.50.53--mathias.haas#ue.sr.se@listserv.nai.com>
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain;
	charset="us-ascii"
Content-Length: 1206
Status: RO


Actually, inspired by your suggestion with a double backslash, I tried to
enter a single frontslash instead - and that worked! So I'm now logging on
to the domain with domainname/username !

Thanks again for the great feedback - Ted, Rick and Steve!

/mathias

-----Ursprungligt meddelande-----
Fran: Rick Murphy [mailto:rmurphy@itm-inst.com]
Skickat: den 27 november 2001 01:49
Till: fwtk-users
Amne: [fwtk-users] Re: Connecting to a W2kl-ftp server


At 11:56 AM 11/26/01 +0100, Mathias Haas wrote:
>The problem is that FWTK doesn't seem to accept account names with a
>backslash in it. Instead it translates the username as DOMAINNAMEUSERNAME,
>i.e. instead of michael\ourdomain you get michaelourdomain.

The command parser that FWTK uses (enargv) "handles" backslashes - it
treats it like a quote character. If you use two backslashes (\\), a single
backslash will be sent.
         -Rick


---
You are currently subscribed to fwtk-users as: mathias.haas@ue.sr.se
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Wed Nov 28 06:08 EST 2001
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id GAA07010
	Wed, 28 Nov 2001 06:08:24 -0500 (EST)
Message-Id: <LISTMANAGER-303-233-2001.11.28-05.13.50--fwtk-archive#lists.tislabs.com@listserv.nai.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.1
Date: Wed, 28 Nov 2001 06:10:28 -0500
To: "fwtk-users" <fwtk-users@listserv.nai.com>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: [fwtk-users] Re: RBL lookups don't work anymore
In-Reply-To: <LISTMANAGER-602-231-2001.11.28-01.04.38--rmurphy#itm-inst.
 com@listserv.nai.com>
Mime-Version: 1.0
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 488
Status: RO

At 11:08 PM 11/27/01 -0800, Michael St. Laurent wrote:
>Are RBL lookups still working for you folks?  They don't seem to work for me
>anymore even if I try them via nslookup.

MAPS now charges a subscription for RBL lookups. See their web page at 
<http://www.mail-abuse.org> for information on how to subscribe.
         -Rick


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Wed Nov 28 09:33 EST 2001
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id JAA07650
	Wed, 28 Nov 2001 09:33:32 -0500 (EST)
From: "Ken Long" <ken@lectrosonics.com>
Organization: Lectrosonics, Inc.
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Date: Wed, 28 Nov 2001 07:41:48 -0700
MIME-Version: 1.0
Content-transfer-encoding: 7BIT
Subject: [fwtk-users] Re: Smap Message: peer dropped connection
Message-ID: <LISTMANAGER-303-237-2001.11.28-08.38.52--fwtk-archive#lists.tislabs.com@listserv.nai.com>
Priority: normal
In-reply-to: <LISTMANAGER-559-230-2001.11.27-18.36.51--ken#lectrosonics.com@listserv.nai.com>
References: <1006853921.9923.2.camel@syntax.dstl.gov.uk>
X-mailer: Pegasus Mail for Win32 (v3.12c)
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain; charset=US-ASCII
Content-Length: 965
Status: RO

Ok, please allow me to show my ignorance here. Is the "envelope sender" 
the same as a custom "reply to" that I can set in my email client?

I use Pegasus Email at home and have my smtp set to the ISP I'm connected 
to but my email identity and pop3 host are set to a different provider. 
This is because I've had the same email address since day 1 on the 
Internet and don't wish to change but switched over to cable modem 
service when it became available.

Regards,
Ken Long

On 27 Nov 2001, at 19:35, Rick Murphy wrote:

> All the patch does is to say that if you're trying to send mail with an 
> envelope sender of "*@yahoo.com", you *must* be coming from a host with a 
> valid reverse DNS somewhere in the yahoo.com domain. So far, that works 
> well for detecting the most common forged domains.


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Wed Nov 28 11:48 EST 2001
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id LAA08054
	Wed, 28 Nov 2001 11:48:23 -0500 (EST)
X-Authentication-Warning: guardian.hartwellcorp.com: mail set sender to <mikes@hartwellcorp.com> using -f
Message-ID: <LISTMANAGER-303-238-2001.11.28-10.53.47--fwtk-archive#lists.tislabs.com@listserv.nai.com>
From: "Michael St. Laurent" <mikes@hartwellcorp.com>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Re: RBL lookups don't work anymore
Date: Wed, 28 Nov 2001 08:58:01 -0800
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 1312
Status: RO

Oh... Rats.  ;-)  Well that explains it then.

I know there are a number of other DNS query type blackhole lists out there
such as: 

http://www.declude.com/JunkMail/Support/ip4r.htm. 

Is there any consensus on which of them would be closest to the MAPS lists
as far as the level of blocking?  Also, which might you recommend?

--------------------
Michael St. Laurent
Hartwell Corporation

[root@earth] root# rm -rf /bin/laden

> -----Original Message-----
> From: Rick Murphy [mailto:rmurphy@itm-inst.com] 
> Sent: Wednesday, November 28, 2001 3:10 AM
> To: fwtk-users
> Subject: [fwtk-users] Re: RBL lookups don't work anymore
> 
> 
> At 11:08 PM 11/27/01 -0800, Michael St. Laurent wrote:
> >Are RBL lookups still working for you folks?  They don't 
> seem to work for me
> >anymore even if I try them via nslookup.
> 
> MAPS now charges a subscription for RBL lookups. See their 
> web page at 
> <http://www.mail-abuse.org> for information on how to subscribe.
>          -Rick
> 
> 
> ---
> You are currently subscribed to fwtk-users as: mikes@hartwellcorp.com
> To unsubscribe send a blank email to 
> leave-fwtk-users-303A@listserv.nai.com
> 

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Wed Nov 28 17:20 EST 2001
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id RAA09203
	Wed, 28 Nov 2001 17:20:42 -0500 (EST)
Message-Id: <LISTMANAGER-303-239-2001.11.28-16.25.50--fwtk-archive#lists.tislabs.com@listserv.nai.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.1
Date: Wed, 28 Nov 2001 17:21:39 -0500
To: "fwtk-users" <fwtk-users@listserv.nai.com>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: [fwtk-users] Re: RBL lookups don't work anymore
In-Reply-To: <3C05225C.219794B0@Lnxw.COM>
Mime-Version: 1.0
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 410
Status: RO

At 09:43 AM 11/28/01 -0800, H.T. Sun wrote:
>Hi,
>
>    Just out of curiosity, what kind of protocol does smap use to pull the
>blackhole lists
>    from the RBL sites ?  (e.g. rbl.maps.vix.com), is it ftp, dns..., etc. ?
DNS lookups.
         -Rick


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Wed Nov 28 19:10 EST 2001
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id TAA09667
	Wed, 28 Nov 2001 19:10:46 -0500 (EST)
Message-Id: <LISTMANAGER-303-240-2001.11.28-18.15.49--fwtk-archive#lists.tislabs.com@listserv.nai.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.1
Date: Wed, 28 Nov 2001 19:18:26 -0500
To: "fwtk-users" <fwtk-users@listserv.nai.com>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: [fwtk-users] Re: Smap Message: peer dropped connection
In-Reply-To: <LISTMANAGER-602-237-2001.11.28-08.38.52--rmurphy#itm-inst.
 com@listserv.nai.com>
Mime-Version: 1.0
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 1240
Status: RO

At 07:41 AM 11/28/01 -0700, Ken Long wrote:
>Ok, please allow me to show my ignorance here. Is the "envelope sender"
>the same as a custom "reply to" that I can set in my email client?

No, it's the address in the "MAIL FROM" transaction. Usually that's the 
"From:" address your recipient will see.

>I use Pegasus Email at home and have my smtp set to the ISP I'm connected
>to but my email identity and pop3 host are set to a different provider.
>This is because I've had the same email address since day 1 on the
>Internet and don't wish to change but switched over to cable modem
>service when it became available.

The reverse lookup check is *only* performed when the domain name of the 
sender matches a list. I verify hotmail, yahoo, and a few other commonly 
forged domains. It would be impractical to do this on a widespread basis. 
In fact, this mail is being sent from a host with no reverse DNS due to an 
incompetent ISP. I'd be blocked by my own code if you enabled 
verify-reverse on me. This is a big hammer that you need to use with 
discretion.
         -Rick


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Wed Nov 28 22:18 EST 2001
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id WAA10261
	Wed, 28 Nov 2001 22:18:50 -0500 (EST)
Message-ID: <LISTMANAGER-303-241-2001.11.28-21.24.08--fwtk-archive#lists.tislabs.com@listserv.nai.com>
From: "Kiyoshi Ohashi" <k-ohashi@hitachi-ul.co.jp>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] About tn-gw
Date: Thu, 29 Nov 2001 12:27:33 +0900
Organization: HITACHI ULSI SYSTEMS CO., LTD.
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.50.4807.1700
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4807.1700
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain;
	charset="iso-2022-jp"
Content-Length: 731
Status: RO

Hello!

I want to control access to Host-C from Host-A. Can the tn-gw control access
to Host-C from Host-A?

(Host-A)--->(tn-gw)--->(Host-B)--->(Host-C)

Any hints?

Thax!

*S*N*O*W***
                   Kiyoshi Ohashi
                   HITACHI ULSI SYSTEMS CO., LTD.
 ' '  _O_/   '     Device Design Center
  '  / |  ''
 '     - '  '      5-22-1, Josuihon-cho, Kodaira-shi,
(~~~~~/ \~~~~) ==  Tokyo, 187-8522 Japan
 ~~~~~~~~~~~~      Voice: +81-(0)42-326-1111 ex.3369
                   Facimile: +81-(0)42-328-4373
                   E-mail: k-ohashi@hitachi-ul.co.jp


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Thu Nov 29 05:46 EST 2001
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id FAA10955
	Thu, 29 Nov 2001 05:46:49 -0500 (EST)
Message-Id: <LISTMANAGER-303-242-2001.11.29-04.52.48--fwtk-archive#lists.tislabs.com@listserv.nai.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.1
Date: Thu, 29 Nov 2001 05:55:04 -0500
To: "fwtk-users" <fwtk-users@listserv.nai.com>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: [fwtk-users] Re: RBL lookups don't work anymore
In-Reply-To: <LISTMANAGER-602-238-2001.11.28-10.53.47--rmurphy#itm-inst.
 com@listserv.nai.com>
Mime-Version: 1.0
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 1723
Status: RO

At 08:58 AM 11/28/01 -0800, Michael St. Laurent wrote:
>Oh... Rats.  ;-)  Well that explains it then.
>
>I know there are a number of other DNS query type blackhole lists out there
>such as:
>
>http://www.declude.com/JunkMail/Support/ip4r.htm.
>
>Is there any consensus on which of them would be closest to the MAPS lists
>as far as the level of blocking?  Also, which might you recommend?

What I use are the lists at relays.osirusoft.com, some outright rejecting 
and some marking for users to decide. The top-level "relays.osirusoft.com" 
has everything listed; only those hosts with address 127.0.0.2 are on their 
relay list, thus the first entry (.relays.osirusoft.com:127.0.0.2).

I'm finding that ORBZ lists more open relays - I'm going to put them in 
mark mode soon for testing.
         -Rick

#
# OSIRUSOFT blocks
#
smap:   block-list "ORL" block .relays.osirusoft.com:127.0.0.2 "%s/%s was found
in the Osirusoft relays list (see http://relays.osirusoft.com/)"
smap:   block-list "ORD" block .dialups.relays.osirusoft.com "%s/%s was 
found in
  the Osirusoft dialups list (see http://relays.osirusoft.com/)"
smap:   block-list "ORS" block .spamsites..relays.osirusoft.com "%s/%s was 
found
  in the Spamhouse blocking list (see http://relays.osirusoft.com/)"
#
smap:   block-list "SBL" mark .spamhaus.relays.osirusoft.com "%s/%s was 
found in
  the SPEWS.ORG spamsource list (see http://www.spamhaus.org/sbl/)"
smap:   block-list "SPEWS" mark .spews.relays.osirusoft.com "%s/%s was found in
the SPEWS.ORG spamsource list (see http://www.spews.org/)"



---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Thu Nov 29 09:10 EST 2001
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id JAA11700
	Thu, 29 Nov 2001 09:10:58 -0500 (EST)
Message-ID: <LISTMANAGER-303-244-2001.11.29-08.14.07--fwtk-archive#lists.tislabs.com@listserv.nai.com>
Date: Thu, 29 Nov 2001 23:17:28 +0900
From: Toshio Kumagai <Toshio_Kumagai@Kumasan.ORG>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Organization: Kumasan.ORG (Kumagai Family, Japan)
X-Mailer: Mozilla 4.75 [ja] (X11; U; SunOS 5.8 i86pc)
X-Accept-Language: ja
MIME-Version: 1.0
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Re: About tn-gw
Content-Transfer-Encoding: 7bit
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Content-Type: text/plain; charset=iso-2022-jp
Content-Length: 1402
Status: RO

Hi Kiyoshi-san,

	What is the role of machine Host-B ?
	Router ?
	Or users at Host-A login to Host-B then login to Host C ?
	Tn-gw would not work if the users log into Host-B first.
	You have to control the access from Host-A to Host-B
	in that case.
	If Host-B acts as a router, then you can control access
	from Host-A to Host-C in most case.

  Regards.

  ###

Kiyoshi Ohashi wrote:
> 
> Hello!
> 
> I want to control access to Host-C from Host-A. Can the tn-gw control access
> to Host-C from Host-A?
> 
> (Host-A)--->(tn-gw)--->(Host-B)--->(Host-C)
> 
> Any hints?
> 
> Thax!
> 
> *S*N*O*W***
>                    Kiyoshi Ohashi
>                    HITACHI ULSI SYSTEMS CO., LTD.
>  ' '  _O_/   '     Device Design Center
>   '  / |  ''
>  '     - '  '      5-22-1, Josuihon-cho, Kodaira-shi,
> (~~~~~/ \~~~~) ==  Tokyo, 187-8522 Japan
>  ~~~~~~~~~~~~      Voice: +81-(0)42-326-1111 ex.3369
>                    Facimile: +81-(0)42-328-4373
>                    E-mail: k-ohashi@hitachi-ul.co.jp
> 
> ---
> You are currently subscribed to fwtk-users as: Toshio_Kumagai@Kumasan.ORG
> To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

-- 
  Toshio Kumagai	TK2959 / TK127-AP
			Toshio_Kumagai@Kumasan.ORG, Japan

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Thu Nov 29 10:03 EST 2001
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id KAA11895
	Thu, 29 Nov 2001 10:03:37 -0500 (EST)
Message-ID: <LISTMANAGER-303-245-2001.11.29-09.08.42--fwtk-archive#lists.tislabs.com@listserv.nai.com>
Date: Fri, 30 Nov 2001 00:12:08 +0900
From: Toshio Kumagai <Toshio_Kumagai@Kumasan.ORG>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Organization: Kumasan.ORG (Kumagai Family, Japan)
X-Mailer: Mozilla 4.75 [ja] (X11; U; SunOS 5.8 i86pc)
X-Accept-Language: ja
MIME-Version: 1.0
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Re: About tn-gw
Content-Transfer-Encoding: 7bit
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Content-Type: text/plain; charset=iso-2022-jp
Content-Length: 2594
Status: RO

Hi Kiyoshi-san and lists,

	Sorry that what I've said was not true.
	In my understand, tn-gw control is based on source IP address.
	So, ALL incoming telnet connsctions have to be controlled
	under tn-gw and netacl (netacl-telnetd).
	Here are tn-gw section of netperm-table on my firewall.
	Authserver is also working with opie.

*:              authserver 192.168.1.4 AUTHPORT

netacl-telnetd: permit-hosts 127.0.0.1 192.168.1.* 192.168.2.* \
	-exec /usr/sbin/in.telnetd
netacl-telnetd: permit-hosts * -exec /usr/local/etc/tn-gw
tn-gw:          permit-hosts * -auth -xok

	Netacl is called from tcpserver (not inetd...inetd is not
	working on my firewall) like this:

tcpserver -vD -c3 -b5 -t3 0 23 /usr/local/etc/netacl telnetd &

	Hope this helps.

  ###

Toshio Kumagai wrote:
> 
> Hi Kiyoshi-san,
> 
>         What is the role of machine Host-B ?
>         Router ?
>         Or users at Host-A login to Host-B then login to Host C ?
>         Tn-gw would not work if the users log into Host-B first.
>         You have to control the access from Host-A to Host-B
>         in that case.
>         If Host-B acts as a router, then you can control access
>         from Host-A to Host-C in most case.
> 
>   Regards.
> 
>   ###
> 
> Kiyoshi Ohashi wrote:
> >
> > Hello!
> >
> > I want to control access to Host-C from Host-A. Can the tn-gw control access
> > to Host-C from Host-A?
> >
> > (Host-A)--->(tn-gw)--->(Host-B)--->(Host-C)
> >
> > Any hints?
> >
> > Thax!
> >
> > *S*N*O*W***
> >                    Kiyoshi Ohashi
> >                    HITACHI ULSI SYSTEMS CO., LTD.
> >  ' '  _O_/   '     Device Design Center
> >   '  / |  ''
> >  '     - '  '      5-22-1, Josuihon-cho, Kodaira-shi,
> > (~~~~~/ \~~~~) ==  Tokyo, 187-8522 Japan
> >  ~~~~~~~~~~~~      Voice: +81-(0)42-326-1111 ex.3369
> >                    Facimile: +81-(0)42-328-4373
> >                    E-mail: k-ohashi@hitachi-ul.co.jp
> >
> > ---
> > You are currently subscribed to fwtk-users as: Toshio_Kumagai@Kumasan.ORG
> > To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com
> 
> --
>   Toshio Kumagai        TK2959 / TK127-AP
>                         Toshio_Kumagai@Kumasan.ORG, Japan
> 
> ---
> You are currently subscribed to fwtk-users as: Toshio_Kumagai@Kumasan.ORG
> To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

-- 
  Toshio Kumagai	TK2959 / TK127-AP
			Toshio_Kumagai@Kumasan.ORG, Japan

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Thu Nov 29 21:56 EST 2001
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id VAA13511
	Thu, 29 Nov 2001 21:56:39 -0500 (EST)
Date: Thu, 29 Nov 2001 22:05:09 -0500 (EST)
From: Ted Keller <keller@bfg.com>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Re: About tn-gw
In-Reply-To: <LISTMANAGER-13-245-2001.11.29-09.08.42--keller#bfg.com@listserv.nai.com>
Message-ID: <LISTMANAGER-303-246-2001.11.29-21.01.43--fwtk-archive#lists.tislabs.com@listserv.nai.com>
MIME-Version: 1.0
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 3063
Status: RO

tn-gw has it's own connection acl loggic.  You do not have to spawn it
from netacl.  inetd can call it directly.

ted keller


On Fri, 30 Nov 2001, Toshio Kumagai wrote:

> Hi Kiyoshi-san and lists,
>
> 	Sorry that what I've said was not true.
> 	In my understand, tn-gw control is based on source IP address.
> 	So, ALL incoming telnet connsctions have to be controlled
> 	under tn-gw and netacl (netacl-telnetd).
> 	Here are tn-gw section of netperm-table on my firewall.
> 	Authserver is also working with opie.
>
> *:              authserver 192.168.1.4 AUTHPORT
>
> netacl-telnetd: permit-hosts 127.0.0.1 192.168.1.* 192.168.2.* \
> 	-exec /usr/sbin/in.telnetd
> netacl-telnetd: permit-hosts * -exec /usr/local/etc/tn-gw
> tn-gw:          permit-hosts * -auth -xok
>
> 	Netacl is called from tcpserver (not inetd...inetd is not
> 	working on my firewall) like this:
>
> tcpserver -vD -c3 -b5 -t3 0 23 /usr/local/etc/netacl telnetd &
>
> 	Hope this helps.
>
>   ###
>
> Toshio Kumagai wrote:
> >
> > Hi Kiyoshi-san,
> >
> >         What is the role of machine Host-B ?
> >         Router ?
> >         Or users at Host-A login to Host-B then login to Host C ?
> >         Tn-gw would not work if the users log into Host-B first.
> >         You have to control the access from Host-A to Host-B
> >         in that case.
> >         If Host-B acts as a router, then you can control access
> >         from Host-A to Host-C in most case.
> >
> >   Regards.
> >
> >   ###
> >
> > Kiyoshi Ohashi wrote:
> > >
> > > Hello!
> > >
> > > I want to control access to Host-C from Host-A. Can the tn-gw control access
> > > to Host-C from Host-A?
> > >
> > > (Host-A)--->(tn-gw)--->(Host-B)--->(Host-C)
> > >
> > > Any hints?
> > >
> > > Thax!
> > >
> > > *S*N*O*W***
> > >                    Kiyoshi Ohashi
> > >                    HITACHI ULSI SYSTEMS CO., LTD.
> > >  ' '  _O_/   '     Device Design Center
> > >   '  / |  ''
> > >  '     - '  '      5-22-1, Josuihon-cho, Kodaira-shi,
> > > (~~~~~/ \~~~~) ==  Tokyo, 187-8522 Japan
> > >  ~~~~~~~~~~~~      Voice: +81-(0)42-326-1111 ex.3369
> > >                    Facimile: +81-(0)42-328-4373
> > >                    E-mail: k-ohashi@hitachi-ul.co.jp
> > >
> > > ---
> > > You are currently subscribed to fwtk-users as: Toshio_Kumagai@Kumasan.ORG
> > > To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com
> >
> > --
> >   Toshio Kumagai        TK2959 / TK127-AP
> >                         Toshio_Kumagai@Kumasan.ORG, Japan
> >
> > ---
> > You are currently subscribed to fwtk-users as: Toshio_Kumagai@Kumasan.ORG
> > To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com
>
> --
>   Toshio Kumagai	TK2959 / TK127-AP
> 			Toshio_Kumagai@Kumasan.ORG, Japan
>
> ---
> You are currently subscribed to fwtk-users as: keller@bfg.com
> To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com
>


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Fri Nov 30 03:19 EST 2001
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id DAA13959
	Fri, 30 Nov 2001 03:19:35 -0500 (EST)
Subject: [fwtk-users] Question about plug-gw
To: "fwtk-users" <fwtk-users@listserv.nai.com>
X-Mailer: Lotus Notes Release 5.0.8  June 18, 2001
Message-ID: <LISTMANAGER-303-247-2001.11.30-02.25.30--fwtk-archive#lists.tislabs.com@listserv.nai.com>
From: juergen.streck@pruftechnik.com
Date: Fri, 30 Nov 2001 09:28:27 +0100
MIME-Version: 1.0
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by lists.tislabs.com id DAA13959
Content-Type: text/plain; charset=iso-8859-1
Content-Length: 1346
Status: RO

Hello,

we are desperately trying to get Sourcegears Source Offsite running with
plug-gw. Source Offsite uses normally port 8888, so it should be no problem
to plug that port through the firewall. But whenever I connect to the
Offsite server, the server immediately closes the connection. There´s a
statement in the help of Source Offsite that "it will only work with
proxies that enables CONNECTS". I contacted support of Sourcegear to ask
them what they mean and here is the answer from them:
> Basically, what we mean by CONNECTS is that the proxy must be configured
to
> allow completely stateless transactions to pass.  Most proxies are
> initially configured to only allow one message at a time to pass.
However,
> SourceOffSite requires an open connection.  This is analogous to SSL
> tunneling.  In fact, the proxy may even offer that as a checkable option.

Can you tell me if that is somehow possible with plug-gw, or is there an
add-on which will enable this kind of connection ?
Thanks in advance for your help.
Regards, Juergen

Juergen Streck
PRÜEFTECHNIK AG
Oskar-Messter-Straße 19-21
85737 Ismaning
www.pruftechnik.com
Tel: +49 (0)89 99616-206
Fax: +49 (0)89 99616-200



---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Fri Nov 30 04:02 EST 2001
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id EAA14053
	Fri, 30 Nov 2001 04:02:59 -0500 (EST)
X-Authentication-Warning: spider.usrconsult.be: mail set sender to <mbardiaux@peaktime.be> using -f
Message-ID: <LISTMANAGER-303-248-2001.11.30-03.08.14--fwtk-archive#lists.tislabs.com@listserv.nai.com>
Date: Fri, 30 Nov 2001 10:11:56 +0100
From: Michel Bardiaux <mbardiaux@peaktime.be>
Organization: Peaktime Belgium S.A.
X-Mailer: Mozilla 4.73 [en] (WinNT; I)
X-Accept-Language: en,fr
MIME-Version: 1.0
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Re: Question about plug-gw
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by lists.tislabs.com id EAA14053
Content-Type: text/plain; charset=iso-8859-1
Content-Length: 2167
Status: RO

juergen.streck@pruftechnik.com wrote:
> 
> Hello,
> 
> we are desperately trying to get Sourcegears Source Offsite running with
> plug-gw. Source Offsite uses normally port 8888, so it should be no problem
> to plug that port through the firewall. But whenever I connect to the
> Offsite server, the server immediately closes the connection. There´s a
> statement in the help of Source Offsite that "it will only work with
> proxies that enables CONNECTS". I contacted support of Sourcegear to ask
> them what they mean and here is the answer from them:
> > Basically, what we mean by CONNECTS is that the proxy must be configured
> to
> > allow completely stateless transactions to pass.  Most proxies are
> > initially configured to only allow one message at a time to pass.
> However,
> > SourceOffSite requires an open connection.  This is analogous to SSL
> > tunneling.  In fact, the proxy may even offer that as a checkable option.
> 
> Can you tell me if that is somehow possible with plug-gw, or is there an
> add-on which will enable this kind of connection ?
> Thanks in advance for your help.
> Regards, Juergen

plug-gw must be started with the "-ssl" option.

Are you able to access secured web pages (i.e. URLs beginning with
https://) from your browser? If so, then you could point "Source
Offsite" to the same port on the firewall that the browser uses as
"secure proxy", usually 443. Or, configure plug-gw on port 8888 the same
way as the one on port 443.

Could you post your related inetd.conf (or init.d scripts) and
netperm-table entries?

> 
> Juergen Streck
> PRÜEFTECHNIK AG
> Oskar-Messter-Straße 19-21
> 85737 Ismaning
> www.pruftechnik.com
> Tel: +49 (0)89 99616-206
> Fax: +49 (0)89 99616-200
> 
> ---
> You are currently subscribed to fwtk-users as: mbardiaux@peaktime.be
> To unsubscribe send a blank email to leave-fwtk-users-725O@listserv.nai.com


-- 
Michel Bardiaux
Peaktime Belgium S.A.  Rue Margot, 37  B-1457 Nil St Vincent
Tel : +32 10 65.44.15  Fax : +32 10 65.44.10

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Fri Nov 30 04:50 EST 2001
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id EAA14126
	Fri, 30 Nov 2001 04:50:33 -0500 (EST)
Subject: [fwtk-users] Re: Question about plug-gw
To: "fwtk-users" <fwtk-users@listserv.nai.com>
X-Mailer: Lotus Notes Release 5.0.8  June 18, 2001
Message-ID: <LISTMANAGER-303-249-2001.11.30-03.55.19--fwtk-archive#lists.tislabs.com@listserv.nai.com>
From: juergen.streck@pruftechnik.com
Date: Fri, 30 Nov 2001 10:58:16 +0100
MIME-Version: 1.0
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by lists.tislabs.com id EAA14126
Content-Type: text/plain; charset=iso-8859-1
Content-Length: 4087
Status: RO


I just added "-ssl" to my plug-gw line in netperm.table AND IT WORKS !
Stupid me ;-) Never thought it could have been so simple. Thanks for the
hint.

Regards, Juergen

Juergen Streck
PRUEFTECHNIK AG
Oskar-Messter-Straße 19-21
85737 Ismaning
www.pruftechnik.com
Tel: +49 (0)89 99616-206
Fax: +49 (0)89 99616-200



                                                                                                              
                    Michel                                                                                    
                    Bardiaux             To:     "fwtk-users" <fwtk-users@listserv.nai.com>                   
                    <mbardiaux@pea       cc:                                                                  
                    ktime.be>            Subject:     [fwtk-users] Re: Question about plug-gw                 
                                                                                                              
                    30.11.2001                                                                                
                    10:11                                                                                     
                    Please respond                                                                            
                    to                                                                                        
                    "fwtk-users"                                                                              
                                                                                                              
                                                                                                              




juergen.streck@pruftechnik.com wrote:
>
> Hello,
>
> we are desperately trying to get Sourcegears Source Offsite running with
> plug-gw. Source Offsite uses normally port 8888, so it should be no
problem
> to plug that port through the firewall. But whenever I connect to the
> Offsite server, the server immediately closes the connection. There´s a
> statement in the help of Source Offsite that "it will only work with
> proxies that enables CONNECTS". I contacted support of Sourcegear to ask
> them what they mean and here is the answer from them:
> > Basically, what we mean by CONNECTS is that the proxy must be
configured
> to
> > allow completely stateless transactions to pass.  Most proxies are
> > initially configured to only allow one message at a time to pass.
> However,
> > SourceOffSite requires an open connection.  This is analogous to SSL
> > tunneling.  In fact, the proxy may even offer that as a checkable
option.
>
> Can you tell me if that is somehow possible with plug-gw, or is there an
> add-on which will enable this kind of connection ?
> Thanks in advance for your help.
> Regards, Juergen

plug-gw must be started with the "-ssl" option.

Are you able to access secured web pages (i.e. URLs beginning with
https://) from your browser? If so, then you could point "Source
Offsite" to the same port on the firewall that the browser uses as
"secure proxy", usually 443. Or, configure plug-gw on port 8888 the same
way as the one on port 443.

Could you post your related inetd.conf (or init.d scripts) and
netperm-table entries?

>
> Juergen Streck
> PRÜEFTECHNIK AG
> Oskar-Messter-Straße 19-21
> 85737 Ismaning
> www.pruftechnik.com
> Tel: +49 (0)89 99616-206
> Fax: +49 (0)89 99616-200
>
> ---
> You are currently subscribed to fwtk-users as: mbardiaux@peaktime.be
> To unsubscribe send a blank email to
leave-fwtk-users-303A@listserv.nai.com


--
Michel Bardiaux
Peaktime Belgium S.A.  Rue Margot, 37  B-1457 Nil St Vincent
Tel : +32 10 65.44.15  Fax : +32 10 65.44.10

---
You are currently subscribed to fwtk-users as:
juergen.streck@pruftechnik.com
To unsubscribe send a blank email to leave-fwtk-users-271H@listserv.nai.com





---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Fri Nov 30 09:38 EST 2001
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id JAA14565
	Fri, 30 Nov 2001 09:38:07 -0500 (EST)
Subject: [fwtk-users] Re: Smap Message: peer dropped connection
From: Tony Gale <gale@syntax.dstl.gov.uk>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Cc: fwtk-users <fwtk-users@listserv.nai.com>
In-Reply-To: <5.1.0.14.0.20011127080104.01f3ba10@mail.itm-inst.com>
Content-Transfer-Encoding: 7bit
X-Mailer: Evolution/0.99.2 (Preview Release)
Date: 28 Nov 2001 11:25:40 +0000
Message-Id: <LISTMANAGER-303-252-2001.11.30-08.43.23--fwtk-archive#lists.tislabs.com@listserv.nai.com>
Mime-Version: 1.0
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain
Content-Length: 1335
Status: RO

On Wed, 2001-11-28 at 00:35, Rick Murphy wrote:
> At 09:38 AM 11/27/01 +0000, Tony Gale wrote:
> >I haven't looked into the code, but am going from the description above.
> >I believe the "correct" way to do this check is to look up the MX record
> >for the envelope senders domain and check it against the address of the
> >sending system.
> >
> >Using a reverse dns lookup is much more likely to fail and to give an
> >incorrect result.
> 
> For the big ISPs that is being used on, that's not the case. A big ISP's 
> outgoing SMTP servers aren't necessarily the same as their incoming servers 
> - but they're very likely to have a valid reverse lookup in their own domain.
> 
> All the patch does is to say that if you're trying to send mail with an 
> envelope sender of "*@yahoo.com", you *must* be coming from a host with a 
> valid reverse DNS somewhere in the yahoo.com domain. So far, that works 
> well for detecting the most common forged domains.

The contra-argument being that some ISPs don't allow you to establish a
reverse DNS for an IP range they have allocated to you.

So, it would be best to do both tests, and catch virtually everyone.

Thanks

-tony



---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Fri Nov 30 11:48 EST 2001
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id LAA15114
	Fri, 30 Nov 2001 11:48:00 -0500 (EST)
Message-ID: <LISTMANAGER-303-253-2001.11.30-10.53.59--fwtk-archive#lists.tislabs.com@listserv.nai.com>
From: Fritsch Jonathan D CONT PSNS <fritschj@PSNS.navy.mil>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] SOCK5
Date: Fri, 30 Nov 2001 08:56:19 -0800
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2653.19)
X-N-Score: scored -400
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 245
Status: RO


 Does FWTK allow SOCK5?  If so, how do you configure for it?

Thank You,
  Jonathan


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Fri Nov 30 11:59 EST 2001
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id LAA15143
	Fri, 30 Nov 2001 11:59:54 -0500 (EST)
Message-ID: <LISTMANAGER-303-254-2001.11.30-11.05.07--fwtk-archive#lists.tislabs.com@listserv.nai.com>
Date: Fri, 30 Nov 2001 12:08:04 -0500
From: Keith Young <kyoung@v-one.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Organization: V-ONE
User-Agent: Mozilla/5.0 (Windows; U; Win98; en-US; rv:0.9.6) Gecko/20011120
X-Accept-Language: en-us
MIME-Version: 1.0
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Re: SOCK5
Content-Transfer-Encoding: 7bit
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Content-Type: text/plain; charset=us-ascii; format=flowed
Content-Length: 457
Status: RO

Fritsch Jonathan D CONT PSNS wrote:

>  Does FWTK allow SOCK5?  If so, how do you configure for it?
> 

Jonathan,


No... if you needs SOCKS v5 support, look here:
	http://www.socks.nec.com/reference/socks5.html

Make sure that you read the license agreement.

-- 
--Keith Young
-kyoung@v-one.com


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

