Firewall Wizards mailing list archives
Re: Securing email by inhibiting urls
From: Mathew Want <imortl1 () gmail com>
Date: Thu, 11 Aug 2011 15:18:52 +1000
Perhaps it may be worth looking at it from the other angle. If you have URL's being accessed from your environment (from emails or other sources) these can be channeled via a proxy on the client end. You could then control the URL categorization and/or blocking via that method. Many proxy services get updates of known bad domains and block these automatically (similar to AV updates). This is not directly tied to the mail system, but should give you an option to still control the outbound requests to attack URL's. Just a thought. -- Regards, Mathew Want On 2 August 2011 04:46, Chris <chughes () l8c com> wrote:
A company I work for has been having great difficulty in securing against email attacks. So far we have disabled access to webmail, implemented rules and processes to block freemail services like hotmail etc until the sender registers the address and of course a spam filter (BrightMail). Attachment filtering is pretty strict as well. The threat that presents the biggest challenge is url links in emails. The common method of attack is an email from somedomain.com where they change one character or otherwise make the address look valid (ie: joe () s0medomain com or j0e () somedomain com etc). I was looking for a way to spot and block hyperlinks but it looks like the only option I have is to filter on these and send them to a spam bin. I’d rather yank the offending hyperlink and replace it with a message of some sort. Unfortunately BrightMail doesn’t offer that capability. Any products that do this or ideas on a solution? Thanks _______________________________________________ firewall-wizards mailing list firewall-wizards () listserv icsalabs com https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
-- "Some things are eternal by nature, others by consequence" _______________________________________________ firewall-wizards mailing list firewall-wizards () listserv icsalabs com https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
Current thread:
- Securing email by inhibiting urls Chris (Aug 10)
- Re: Securing email by inhibiting urls Mathew Want (Aug 11)
- Re: Securing email by inhibiting urls Chris (Aug 11)
- Re: Securing email by inhibiting urls Marcus Ranum (Aug 11)
- Re: Securing email by inhibiting urls Jean-Denis Gorin (Aug 12)
- Re: Securing email by inhibiting urls Marcus Ranum (Aug 12)
- Re: Securing email by inhibiting urls Chris (Aug 11)
- Re: Securing email by inhibiting urls Timothy Shea (Aug 11)
- Re: Securing email by inhibiting urls Mathew Want (Aug 11)
- Re: Securing email by inhibiting urls Chris (Aug 11)
- Re: Securing email by inhibiting urls Kurt Buff (Aug 11)
- Re: Securing email by inhibiting urls Victor Williams (Aug 11)