Re: SV: Website link for 212.242.219.138

Alexey Lobanov <[email protected]>
Newsgroups gmane.mail.spam.dsbl.admin
Message-ID <[email protected]>
Hello.

On 09/07/2005 03:21 PM, Brian Nielsen wrote:

> Hi Alexey
> 
> Thank you for your reply...
> 
> Your engine must be better that many others on the list from dnsstuff.com.. because they say good for it..
> 
> I will try to look into it when I get home from work.. 
> 
> Do you have a link to where I can make a quick test with your engine?

To my knowledge, no. The test from my location is in progress, and you
will see the fresh results at DSBL.

But the essence of problem is simple enough, and you can test anything
by hands if you have any kind of shell account anywhere outside of
212.242.219.138 site. Use telnet and try any *existing* address in your
domain in MAIL FROM. A properly configured Mdaemon must either demand
authentification or say that any mail *from* bknnet.dk is disallowed. If
it accepts the forged sender address, you are vulnerable; and this is
the default in all Mdaemons from early versions up to current 8.x. So
why I diagnoze the bug in brains :-)

Alexey


> 
> /Brian Nielsen :-)
> 
> -----Oprindelig meddelelse-----
> Fra: Alexey Lobanov [mailto:[email protected]] 
> Sendt: 7. september 2005 13:19
> Til: Brian Nielsen
> Cc: [email protected]; [email protected]
> Emne: Re: [DSBL-Contact] Website link for 212.242.219.138
> 
> Hello.
> 
> Brian Nielsen wrote:
> 
> 
>>This server has never relayed mail!
>>
>>
>>
>>Your scanner just thought it did,
> 
> 
> The "scanner" does not try to interpret any server messages. DSBL only
> trusts to real e-mails delivered from your mailserver to DSBL
> mailserver. And the explicit evidence is shown in "Messages from this
> host" section at http://dsbl.org/listing?212.242.219.138. A test message
> relayed from Poland to US via 212.242.219.138.
> 
> 
>>because of the servers old welcome
>>message, which told people that relay is prohibited and reported to
>>the police...  Now I have removed that message, and tries to remove
>>me.. but I can't get the email, because it goes to my ISP... Please
>>correct that.
> 
> 
> To my knowledge, all Mdaemon versions are known to be insecure by
> default because of some stable bugs in author's brains. It just trusts
> sender's domain in MAIL FROM. Surely, there are semi-documented
> workarounds to make it secure; I hope, you have implemented them already.
> 
> Best,
> Alexey
> DSBL volunteer
> 
> 
> 
>>
>>
>>Med venlig hilsen Brian Kenneth Nielsen
>>
>>
>>
>>[email protected] Direct: +45 39 13 02 06
>>
>>MONDO A/S Bådehavnsgade 6 DK-2450 København S Tel +45 39 13 02 00 Fax
>>+45 39 13 02 01 www.mondo.dk
>><file:///D:\Documents%20and%20Settings\jhe.MLAN\Application%20Data\Microsoft\Signatures\www.mondo.dk>
>>
>>
>>
>>
>>
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.