mailfront : only allow allow authenticated user address as MAIL FROM (Return-Path) ?

Olivier Mueller <[email protected]>
Newsgroups gmane.mail.qmail.general
Message-ID <[email protected]>
Hi,

I hope you all had a nice summer !

I just got a few cases where user accounts were compromised (weak 
password or hacked pc's + stolen passwords) and then used to send 
massive spams, for example last night:

tcpserver: pid 20727 from 195.223.y.y
tcpserver: ok 20727 omicron:62.48.x.x:25 :195.223.y.y::51731
mailfront[20727]: SASL AUTH LOGIN username=info sys_username=o67a123
domain=example.org
mailfront[20727]: MAIL FROM:<****@comcast.net>
mailfront[20727]: RCPT TO:<****@yahoo.com>
mailfront[20727]: RCPT TO:<****@eddy.foamex.com>
mailfront[20727]: RCPT TO:<****@lifeway.com>
(....)
mailfront[20727]: RCPT TO:<****@clorox.com>
mailfront[20727]: RCPT TO:<****@yahoo.com>
mailfront[20727]: RCPT TO:<****@yahoo.com>


As you can see, the "MAIL FROM:" part used as Return-Path is completely 
forged.  I just checked the docs to try to find a way to prevent this 
directly with mailfront and its plugins, but with no success yet : have 
anyone here using mailfront implemented this ? If yes, a short message 
would be great, thanks !

Next step would be to check if the Header-"From: " field is also valid, 
but this would most probably be more complex.


Kind regards & a nice week to you,
Olivier
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.