Hi all,
There are a number of measures we take locally to limit the damage
that an ax.25 spoofer can cause

1. All "callsign" users have only read/write access to the local
2. All users who have any greater access (including the sysop) have
usernames greater than 6 characters. This means the username cannot
be put in an ax.25 callsign field, and therefore all such users must
use telnet to get into the bbs; with its associated password
3. All users who have the access as stated in (2) have their
"callsign" only entries set with 128 permission in ftpusers, thus
preventing spoofing.

This seems to work for us.
73 Gareth

