LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-14-2006, 10:40 AM   #1
~=gr3p=~
Member
 
Registered: Feb 2005
Location: ~h3av3n~
Distribution: RHEL 4, Fedora Core 3,6,7 Centos 5, Ubuntu 7.04
Posts: 227

Rep: Reputation: 30
3 ???: Iptables, ClamAV+qmail, password program


I have 3 questions;

1) Is there any way/program other than iptables to bind an IP to a MAC address bcoz i have certain machines on my network to whom i allow unrestricted access to certain resources and i want to avoid IP spoofing. I can do with iptables but jus wannan know alternate ways

2) I use qmail-scanner with clamav and my company's policy is to reject certain extensions like archive extension (zip,rar etc) as attachments. But i find it can be easily bypassed by changing the file extensions to say an allowed extension like .doc . how can i stop this.

3) Is there a browser based program like this:
http://sarg.sourceforge.net/chetcpasswd.php

that will let my users change thier qmail (smtp/pop) password remotely. Currently i'm using OmailAdmin but i wan't just a simple password change only webpage.

thank you
 
Old 01-14-2006, 10:59 AM   #2
erimar77
Member
 
Registered: Jan 2006
Posts: 76

Rep: Reputation: 15
i would check out http://qmailrocks.com/

there's craploads of features that might interest you
 
Old 01-15-2006, 08:40 AM   #3
~=gr3p=~
Member
 
Registered: Feb 2005
Location: ~h3av3n~
Distribution: RHEL 4, Fedora Core 3,6,7 Centos 5, Ubuntu 7.04
Posts: 227

Original Poster
Rep: Reputation: 30
Is ther a solution for my 2 question thank you. It can be easily bypassed by changing the file extions. Why can't clamav detect the file as zip even if it's renamed to .doc extension and then block it.
 
Old 01-16-2006, 12:03 AM   #4
erimar77
Member
 
Registered: Jan 2006
Posts: 76

Rep: Reputation: 15
because when a zip file is renamed to .doc it's no longer a zip file anymore. it's a .doc file... sure no office program will open it... but that's just the way it is. there would be so much overhead on mail servers if they had to attempt to rename every attachment to every known file extension just to see which correct extension it is. if it could even do that... and what about mac osx... you don't even need filename extensions
 
Old 01-16-2006, 12:14 AM   #5
~=gr3p=~
Member
 
Registered: Feb 2005
Location: ~h3av3n~
Distribution: RHEL 4, Fedora Core 3,6,7 Centos 5, Ubuntu 7.04
Posts: 227

Original Poster
Rep: Reputation: 30
the reason i ask this is coz in my previous organization i used to rename the blocked zip archives to doc and some prgram running with qmail used to block it even then !!! now i can't ask that administrator how he did it or what he used ? may be the program cud scan it's header
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
qmail-pop3d password authentication Limowreck Linux - Software 2 04-21-2006 08:51 PM
qmail + spamassassin + clamav in fedora core3 inaki Linux - Software 1 04-14-2005 09:56 PM
Qmail-password errors with telnet 110 Wolfy Linux - Software 2 01-28-2005 08:43 PM
Perl Script Program (need) : SpamAssassin-ClamAV-Procmail-Howto cyberjames Slackware 8 01-27-2005 11:53 AM
qmail +qmail-qfilter + qmail-scanner-queue+qmail-user-masq.pl problem countcobolt Linux - Networking 0 07-08-2004 11:29 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:59 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration