Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Blocking mass mailings caused by viruses |
|---|---|
| Date: | Fri, 14 Oct 2005 08:15:51 -0700 |
Larry,
I suggest using an SMTP proxy, preferably one that scans for malware,
for all inbound and outbound SMTP traffic. We use McAfee's e500
appliances. All outbound SMTP is blocked at the firewall if it doesn't
originate from our proxy. Worms and such will not use the proxy, but
pre-authorized connections are configured to use it. Some administration
is required to maintain lists of authorized connections, and correctly
configure clients, but it does solve the problem. We gain the added
benefit of perimeter mail virus blocking, spam blocking, attachment and
content filtering, etc..
- Dan
Dan Lynch, CISSP
Information Technology Analyst
County of Placer
Auburn, CA
It is often easier to not do something dumb than it is to do something
smart.
-- Marcus Ranum
"Erdahl, Larry E" <Larry.Erdahl@allina.com> 10/12/2005 8:31:06 AM
Over the past month we've been blacklisted by Spamhaus several times because of infected workstations and laptops (contractors and consultants) sending out mass mailings. My management doesn't want to block port 25 because we have a handful of physicians who are using POP mail. Does anyone know of an IDS, IPS, firewall, router ACLs, etc... that will block outgoing SMTP traffic, based on abnormal traffic volume? Thanks in advance! Larry E. Erdahl IS Security Specialist Allina Hospital & Clinics Office (612)775-1273 Cell (612)804-7324 larry.erdahl@allina.com This message contains information that may be confidential and privileged. Unless you are the addressee (or authorized to receive for the addressee), you may not use, copy or disclose to anyone the message or any information contained in the message. If you have received the message in error, please advise the sender by reply e-mail and delete the message.
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: Blocking mass mailings caused by viruses, Derick Anderson |
|---|---|
| Next by Date: | Re: Blocking mass mailings caused by viruses, David Nichols |
| Previous by Thread: | RE: Blocking mass mailings caused by viruses, Derick Anderson |
| Next by Thread: | RE: Blocking mass mailings caused by viruses, James Allen - Sherman Oaks (Senior Network Administrator) |
| Indexes: | [Date] [Thread] [Top] [All Lists] |