Re: Website link for 213.115.133.197

Alexey Lobanov <[email protected]>
Newsgroups gmane.mail.spam.dsbl.admin
Message-ID <[email protected]>
Philip wrote:

> What the hell is going on?

The modern commercial software quality level and vendor responsibility
level. Nothing more.

> Trendmicro says we dont have any trojans or 
> viruses on this machine anymore

More exactly, th means that there are no viruses which are (1) known to
TM and (2) detectable by TM in running form.

In practice, we know that this machine was owned by viruses on August
17. You should know better what had happened since that. Possibly, you
have cleaned everything successfully.

> and ORDB.org says we are not an open relay 
> efter testing.

So, ORDB tests are not full. Please be sure that real spammers know
about this persistent flaw in Mdaemon.

> What should i do? Use another mailserver? Wich one would you 
> recommend? We are a small business.

SMTP server is not something exotic or expensive now. There is a dozen
of well-known industry-standard free multi-platform solutions: Sendmail,
Qmail, Exim, Postfix, Zmailer, etc.

If you are restricted with MS-Windows platform, you may wish to look at
http://www.pmail.com/overviews/ovw_mercury.htm
This program is quite old (I used it in Netware in 1996!) but still
fully-functional and quite secure. No payment is required.

Alexey

>  Thanks,
> Philip J.
> 
>  On 9/6/05, Alexey Lobanov <[email protected]> wrote: 
> 
>>Hi Philip.
>>
>>Philip wrote:
>>
>>
>>>THEIRS that was faulty. Hope they agree to click the link, if they say 
>>
>>no we
>>
>>>will remain in your database and we will not be able to reach thousands 
>>
>>and
>>
>>>thousands of e-mail adresses from our perfectly secure server.
>>
>>Oops. It is really insecure now, even if the trojan incident is solved.
>>See fresh relayed messages at http://dsbl.org/listing?213.115.133.197
>>
>>The known workarounds are:
>>
>>1. You may set authentification requirement with strong passwords for
>>ALL accounts, both real and built-in. Pop-Before-SMTP or SMTP AUTH, no
>>matter.
>>
>>2. You may completely prohibit to accept any mail from your domain from
>>outside of your LAN.
>>
>>3. Finally, you may trash Mdaemon. This security flaw lasts since the
>>very first versions, and the vendors simply deny it.
>>
>>My personal advice is #3.
>>
>>Alexey
>>
>>
>>>Well, that was all. Thanks.
>>>Philip J.
>>>
>>
>>
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.