RE: Securing Sendmail 8.11.6-23 from spammers

"Keith Mastin" <[email protected]>
Newsgroups gmane.linux.redhat.release.enigma
Message-ID <[email protected]>
<snip>
> Regarding the users, if they are local users of the machine (local
> accounts in the mail server) make sure that the access file in /etc/mail
> directory contains the localhost. Add to that file also the IP addresses
> of the client machines in the internal LAN. Than generate a new
> access.db file that sendmail will use. At the same time generate a new
> sendmail.cf configuration file starting with sendmail.mc. In this .mc
> file make sure the feature to RELAY_HOSTS_ONLY is configured. Disable
> relaying based on MX and to accept unresolvable domains. At the end
> restart the sendmail service.

Wow. I don't want to start a flame war here, but this is so complicated in
comparison to what I go through with postfix.

Please, everyone running sendmail: update yor version to the latest
release. It fixes a huge security hole that's implicit in the code (can't
be configured out). The info went public yesterday, so every script-kiddie
out there is working overtime to check your system.

-- 
Keith Mastin
BeechTree Information Technology Services Inc.
Toronto, Canada
(416)696-6070
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.