Re: User validation before scanning the mail?

Jason Haar <[email protected]>
Newsgroups gmane.mail.qmail.scanner
Organization Trimble Navigation Ltd.
Message-ID <[email protected]>
Lampa wrote:
> Hello,
>
> use shupp toaster (www.shupp.org/toaster), implement patch chkuser
> (http://www.interazioni.it/opensource/chkuser/) or there are other
> mechanism (for example using badmailto or oposite - using only valid
> emails - eg create list of all emails you have).
>   
i.e. this is such a fundamental problem that it must be dealt with at
the Qmail level instead of within Qmail-Scanner. With the overhead of
running perl, AVs and (especially) SpamAssassin, it just isn't
appropriate to do this within Qmail-Scanner. Doing it within Qmail
itself (i.e. a patch) will remove a huge amount of traffic from even
getting to Qmail-Scanner.

I'd also suggest looking at the RECIPIENTS extension on
http://www.fehcom.de/qmail/qmail.html

-- 
Cheers

Jason Haar
Information Security Manager, Trimble Navigation Ltd.
Phone: +64 3 9635 377 Fax: +64 3 9635 417
PGP Fingerprint: 7A2E 0407 C9A6 CAF6 2B9F 8422 C063 5EBB FE1D 66D1


-------------------------------------------------------------------------
This SF.net email is sponsored by: Splunk Inc.
Still grepping through log files to find problems?  Stop.
Now Search log events and configuration files using AJAX and a browser.
Download your FREE copy of Splunk now >> http://get.splunk.com/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.