Re: mailfront : only allow allow authenticated user address as MAIL FROM (Return-Path) ?

Erwin Hoffmann <[email protected]>
Newsgroups gmane.mail.qmail.general
Message-ID <[email protected]>
Hi Olivier,

I think I solved that problem partially with my approach 'Mail From: Adress Verification' (MAV).

There is a separate patch against qmail available, though it is part of my former 'Spamcontrol' patch and now -- of course -- s/qmail.

http://fehcom.de/sqmail.html (-> qmail -> MAV).

Best regards.
--eh.


> Am 30.08.2016 um 16:53 schrieb Olivier Mueller <[email protected]>:
> 
> Hi,
> 
> I hope you all had a nice summer !
> 
> I just got a few cases where user accounts were compromised (weak password or hacked pc's + stolen passwords) and then used to send massive spams, for example last night:
> 
> tcpserver: pid 20727 from 195.223.y.y
> tcpserver: ok 20727 omicron:62.48.x.x:25 :195.223.y.y::51731
> mailfront[20727]: SASL AUTH LOGIN username=info sys_username=o67a123
> domain=example.org
> mailfront[20727]: MAIL FROM:<****@comcast.net>
> mailfront[20727]: RCPT TO:<****@yahoo.com>
> mailfront[20727]: RCPT TO:<****@eddy.foamex.com>
> mailfront[20727]: RCPT TO:<****@lifeway.com>
> (....)
> mailfront[20727]: RCPT TO:<****@clorox.com>
> mailfront[20727]: RCPT TO:<****@yahoo.com>
> mailfront[20727]: RCPT TO:<****@yahoo.com>
> 
> 
> As you can see, the "MAIL FROM:" part used as Return-Path is completely forged.  I just checked the docs to try to find a way to prevent this directly with mailfront and its plugins, but with no success yet : have anyone here using mailfront implemented this ? If yes, a short message would be great, thanks !
> 
> Next step would be to check if the Header-"From: " field is also valid, but this would most probably be more complex.
> 
> 
> Kind regards & a nice week to you,
> Olivier
> 
> 

Dr. Erwin Hoffmann | FEHCom | http://www.fehcom.de | PGP Key-Id: EE00CF65
signature.asc (application/pgp-signature, 842 B)
-----BEGIN PGP SIGNATURE-----
Comment: GPGTools - https://gpgtools.org

iQIcBAEBCgAGBQJXzWKZAAoJEIP8+SDuAM9lMIIP/2NSWnyEQHgU1x3uteMU1NwM
hmAdrvib4iYKPi2dIzgMUNxny9SY+VBaJ8xmz66AzHetxlX68PMoqcAg+np5PbAu
Jb8K86XaPL3B+TftwTEjv8Mq+MyxBi9A6tReMiuqdE8fDslRcfzk81LkZaBGQ823
/f5mmjdKRvK9FGwTgUpjgvkdzFo2/G4YVq5MsapBlyATawWr18k9mh58rtUae6XE
cISjuYljnm/2bAP6eDBBuMZWpq2PXpUbgZD+MLzqz2w54J3FPvEnNUgXdjiw1Zu9
jpJm6kJeXEvxOdZ77XCWr/Mw+qjfeZ453HKVEOnaIw0NkQuAowZA1TTX4uopfoSu
n+My5kQebjg3XuA+MvtswZBTjlT30CsP0ltTS3mAZZUN7aQ1+k4s6N5Zzaq4/Uwe
y9Vx4OrA1k6dm6wnBAktEIhdx3d/m3vNFFZyna64iHiTXa3zgk+TONkaE63UF4Fu
7hhBaeWsfTVIY1wqkK7SRCdQKKSjMrm91I+1i86syD5l1nK0eV0zoY0waWybEKIQ
Doa9ke2mTsD1LYKez1qU98tg9VduLaWcwq+j9BZwKwsgwYwW+aNUso6Yj4MAgbfJ
LLFC/EWLwh2GPKzpRS4DApALkFyl/2FzlSSXUNIrtajg+qQCKHFuBemLRW5ZMM3f
o04/DNjR84fP5IVR25rn
=ngdR
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.