R: [Security-Discuss] Problems of SPAM with Postfix
"Leo Mantovani" <[email protected]>
| Newsgroups | gmane.linux.mandrake.security.general |
|---|---|
| Message-ID | <006201c44d68$50b54110$0100a8c0@leo> |
Hi Leonardo, an open relay is one of the *worse* things in the spam nightmare. Open relay means that everybody can send an email to your server for a destination which is NOT local to you and YOUR mail server "relays" it to the final destination. E.g. I send a message to you mailserver with destination [email protected] and your mail server "relays" it to aa.bb. SMTP lacks in tracking mail path ... only THE LAST smtp server is recorded in the meassage header, the result is that the destination aa.bb of the example above will see *you* as sender (I'm not speaking about the "FROM" field, where everybody can write what he wants, but the "RECEIVED" field) ... and the original SMTP sender "disappears". A correctly configured SMTP mail server allows to relay mails only from "trusted" hosts, e.g. only the IP addresses of your local lan. Any SMTP server has such feature, search in the manual of the SMTP server you use. Hope this help Leo -----Messaggio originale----- Da: security-discuss-owner-J4tZAbal8pkzaQFa27Lw39BPR1lH4CV8@public.gmane.org [mailto:security-discuss-owner-J4tZAbal8pkzaQFa27Lw39BPR1lH4CV8@public.gmane.org]Per conto di Tommaso Leonardi Inviato: martedi 8 giugno 2004 16.38 A: security-discuss-J4tZAbal8pkzaQFa27Lw39BPR1lH4CV8@public.gmane.org Oggetto: Re: [Security-Discuss] Problems of SPAM with Postfix Thankyou for your help, but i still don't understand one thing: what is exactly an open relay? And is it a good thing to have one? Thankyou for your help and for your patience... Matt Parker wrote: >On Tue, 2004-06-08 at 14:01, Tommaso Leonardi wrote: > > >>-----BEGIN PGP SIGNED MESSAGE----- >>Hash: SHA1 >> >> >> >>Good day list, >>I'm not so sure I'm on topic, however I'm so desperate that I'll ask >>your help. >>I set up a little mail server NOT for personal use; I give mailboxes >>to 20 or maybe 30 people I know, but I expect to have in three or >>four month about 100 mailboxes. My biggest problem is the spam. I >>didn't think the spam was a so big problem and I understimate it. The >>result is that i found more than 4000 massages in my mail queue to a >>Yahoo server in the Est. I installed Spamassassin and Anomy Sanitizer >>according to this tutorial >>(http://advosys.ca/papers/postfix-filtering.html) but the problem is >>still surviving.... I'm afraid to be in some black list because of the >>thousand of spam massages i sent...is it possible? I considered also >>the possibility to use smtpd SASL authentication, but i though that if >>the other provider in the network don't use it, there must be another >>solution.... >> >>Please help me.....thankyou very much in advance and sorry if I'm off >>topic, >> >>Tommaso Leonardi >> >> > >Sounds like you might be running an open relay. Go here - >http://www.abuse.net/relay.html - to test it. > >Also, you might want to think about using the blocklists at your end. >http://www.securitysage.com has a good tutorial. I've found blocklists >to be the only really effective way of blocking spam - especially the >SORBS one that blocks all mail from dynamic IP addresses. > >Matt > > > >------------------------------------------------------------------------ > >____________________________________________________ >Want to buy your Pack or Services from MandrakeSoft? >Go to http://www.mandrakestore.com >Join the Club : http://www.mandrakeclub.com >____________________________________________________ > >
message.footer
(text/plain, 239 B)
____________________________________________________ Want to buy your Pack or Services from MandrakeSoft? Go to http://www.mandrakestore.com Join the Club : http://www.mandrakeclub.com ____________________________________________________