Re: Web host spam vs spam filters

Chris Lewis <[email protected]> Fri, 21 Jun 2013 22:36:26 -0400
Newsgroups gmane.ietf.asrg
Message-ID <[email protected]>
On 06/21/2013 10:53 AM, Alessandro Vesely wrote:

> OTOH, while firewalls on Windows boxes tend to maintain lits of what
> processes are authorized to do outbound connections, on *nix servers the
> concept is different.  But Linux iptables has an xt_owner module that
> matches on a uid range, so, beside blocking outbound port 25 on
> non-MTAs, one could block attempts to send mail by wrong user-ids on
> MTAs.

That works well.  It's one of the first things we advise, and there are 
several packages that do just this.

HOWEVER, it's hard to do on some boxes, and complex CMS software can 
sometimes clobber such configurations, and SOMETIMES they insist on 
letting httpd or apache or nobody send email because some of their 
clients have stupid SMTP scripts.

-
This is the asrg mailing list.  To change your subscription settings, see
http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org