Re: Website link for 213.115.133.197
Philip <[email protected]>
| Newsgroups | gmane.mail.spam.dsbl.admin |
|---|---|
| Message-ID | <[email protected]> |
Wow, this really sucks. Thanks anyway, guess were scewed then if we cant trust Trendmicro or ORDB.. On 9/6/05, Alexey Lobanov <[email protected]> wrote: > > Philip wrote: > > > What the hell is going on? > > The modern commercial software quality level and vendor responsibility > level. Nothing more. > > > Trendmicro says we dont have any trojans or > > viruses on this machine anymore > > More exactly, th means that there are no viruses which are (1) known to > TM and (2) detectable by TM in running form. > > In practice, we know that this machine was owned by viruses on August > 17. You should know better what had happened since that. Possibly, you > have cleaned everything successfully. > > > and ORDB.org says we are not an open relay > > efter testing. > > So, ORDB tests are not full. Please be sure that real spammers know > about this persistent flaw in Mdaemon. > > > What should i do? Use another mailserver? Wich one would you > > recommend? We are a small business. > > SMTP server is not something exotic or expensive now. There is a dozen > of well-known industry-standard free multi-platform solutions: Sendmail, > Qmail, Exim, Postfix, Zmailer, etc. > > If you are restricted with MS-Windows platform, you may wish to look at > http://www.pmail.com/overviews/ovw_mercury.htm > This program is quite old (I used it in Netware in 1996!) but still > fully-functional and quite secure. No payment is required. > > Alexey > > > Thanks, > > Philip J. > > > > On 9/6/05, Alexey Lobanov <[email protected]> wrote: > > > >>Hi Philip. > >> > >>Philip wrote: > >> > >> > >>>THEIRS that was faulty. Hope they agree to click the link, if they say > >> > >>no we > >> > >>>will remain in your database and we will not be able to reach thousands > >> > >>and > >> > >>>thousands of e-mail adresses from our perfectly secure server. > >> > >>Oops. It is really insecure now, even if the trojan incident is solved. > >>See fresh relayed messages at http://dsbl.org/listing?213.115.133.197 > >> > >>The known workarounds are: > >> > >>1. You may set authentification requirement with strong passwords for > >>ALL accounts, both real and built-in. Pop-Before-SMTP or SMTP AUTH, no > >>matter. > >> > >>2. You may completely prohibit to accept any mail from your domain from > >>outside of your LAN. > >> > >>3. Finally, you may trash Mdaemon. This security flaw lasts since the > >>very first versions, and the vendors simply deny it. > >> > >>My personal advice is #3. > >> > >>Alexey > >> > >> > >>>Well, that was all. Thanks. > >>>Philip J. > >>> > >> > >> > > > >