Re: ietf-nntp BCP for RFC977 server/RFC1036 interaction

"William H. Magill" <magill@isc.upenn.edu> Thu, 19 December 1996 14:10 UTC

Received: from cnri by ietf.org id aa00035; 19 Dec 96 9:10 EST
Received: from ACADEM2.ACADEM.COM by CNRI.Reston.VA.US id aa09535; 19 Dec 96 9:10 EST
Received: (from majordomo@localhost) by academ2.academ.com (8.8.3/8.7.3) id IAA15049 for ietf-nntp-outgoing; Thu, 19 Dec 1996 08:05:47 -0600 (CST)
X-Authentication-Warning: academ2.academ.com: majordomo set sender to owner-ietf-nntp using -f
Received: from academ.com (root@ACADEM.COM [198.137.249.2]) by academ2.academ.com (8.8.3/8.7.3) with ESMTP id IAA15044 for <ietf-nntp@ACADEM2.ACADEM.COM>; Thu, 19 Dec 1996 08:05:44 -0600 (CST)
Received: from staff.dccs.upenn.edu (STAFF.DCCS.UPENN.EDU [130.91.72.67]) by academ.com (8.8.3/8.7.1) with ESMTP id IAA13974 for <ietf-nntp@academ.com>; Thu, 19 Dec 1996 08:05:43 -0600 (CST)
Received: (from magill@localhost) by staff.dccs.upenn.edu (8.8.4/8.7.3) id JAA00972; Thu, 19 Dec 1996 09:05:42 -0500
Date: Thu, 19 Dec 1996 09:05:42 -0500
From: "William H. Magill" <magill@isc.upenn.edu>
Message-Id: <199612191405.JAA00972@staff.dccs.upenn.edu>
to: ietf-nntp@academ.com
Subject: Re: ietf-nntp BCP for RFC977 server/RFC1036 interaction
Sender: owner-ietf-nntp@academ.com
Precedence: bulk

>   The intention was that IHAVE would only be used by news neighbors, never
>   by clients.  The headers in an article arriving by IHAVE would not be
>   tampered with except to prefix the Path line.
>
This may be a comment based on ignorance on my part (being an interested
and effected party, not an expert), but it is my understanding that there is
no protocol distinction between client adjacent-server.  

That is to say, nothing defines a session as being between two peers and
therefore limited to command set A; or between a server and a prospective
or legitimate client and therefore limited to command set B.

Or, put another way, nothing prevents a client from issuing server commands
and vice versa.

And that this lack provides one of the easiest mechanisms for article
forgery.

T.T.F.N.
William H. Magill                          Senior Systems Administrator
Information Services and Computing (ISC)   University of Pennsylvania
Internet: magill@isc.upenn.edu             magill@acm.org
          magill@upenn.edu                 http://pobox.upenn.edu/~magill/