Re: Website link for 213.115.133.197
Alexey Lobanov <[email protected]>
| Newsgroups | gmane.mail.spam.dsbl.admin |
|---|---|
| Message-ID | <[email protected]> |
Philip wrote: > What the hell is going on? The modern commercial software quality level and vendor responsibility level. Nothing more. > Trendmicro says we dont have any trojans or > viruses on this machine anymore More exactly, th means that there are no viruses which are (1) known to TM and (2) detectable by TM in running form. In practice, we know that this machine was owned by viruses on August 17. You should know better what had happened since that. Possibly, you have cleaned everything successfully. > and ORDB.org says we are not an open relay > efter testing. So, ORDB tests are not full. Please be sure that real spammers know about this persistent flaw in Mdaemon. > What should i do? Use another mailserver? Wich one would you > recommend? We are a small business. SMTP server is not something exotic or expensive now. There is a dozen of well-known industry-standard free multi-platform solutions: Sendmail, Qmail, Exim, Postfix, Zmailer, etc. If you are restricted with MS-Windows platform, you may wish to look at http://www.pmail.com/overviews/ovw_mercury.htm This program is quite old (I used it in Netware in 1996!) but still fully-functional and quite secure. No payment is required. Alexey > Thanks, > Philip J. > > On 9/6/05, Alexey Lobanov <[email protected]> wrote: > >>Hi Philip. >> >>Philip wrote: >> >> >>>THEIRS that was faulty. Hope they agree to click the link, if they say >> >>no we >> >>>will remain in your database and we will not be able to reach thousands >> >>and >> >>>thousands of e-mail adresses from our perfectly secure server. >> >>Oops. It is really insecure now, even if the trojan incident is solved. >>See fresh relayed messages at http://dsbl.org/listing?213.115.133.197 >> >>The known workarounds are: >> >>1. You may set authentification requirement with strong passwords for >>ALL accounts, both real and built-in. Pop-Before-SMTP or SMTP AUTH, no >>matter. >> >>2. You may completely prohibit to accept any mail from your domain from >>outside of your LAN. >> >>3. Finally, you may trash Mdaemon. This security flaw lasts since the >>very first versions, and the vendors simply deny it. >> >>My personal advice is #3. >> >>Alexey >> >> >>>Well, that was all. Thanks. >>>Philip J. >>> >> >> >