Re: SV: Website link for 212.242.219.138
Alexey Lobanov <[email protected]>
| Newsgroups | gmane.mail.spam.dsbl.admin |
|---|---|
| Message-ID | <[email protected]> |
Hello. On 09/07/2005 03:21 PM, Brian Nielsen wrote: > Hi Alexey > > Thank you for your reply... > > Your engine must be better that many others on the list from dnsstuff.com.. because they say good for it.. > > I will try to look into it when I get home from work.. > > Do you have a link to where I can make a quick test with your engine? To my knowledge, no. The test from my location is in progress, and you will see the fresh results at DSBL. But the essence of problem is simple enough, and you can test anything by hands if you have any kind of shell account anywhere outside of 212.242.219.138 site. Use telnet and try any *existing* address in your domain in MAIL FROM. A properly configured Mdaemon must either demand authentification or say that any mail *from* bknnet.dk is disallowed. If it accepts the forged sender address, you are vulnerable; and this is the default in all Mdaemons from early versions up to current 8.x. So why I diagnoze the bug in brains :-) Alexey > > /Brian Nielsen :-) > > -----Oprindelig meddelelse----- > Fra: Alexey Lobanov [mailto:[email protected]] > Sendt: 7. september 2005 13:19 > Til: Brian Nielsen > Cc: [email protected]; [email protected] > Emne: Re: [DSBL-Contact] Website link for 212.242.219.138 > > Hello. > > Brian Nielsen wrote: > > >>This server has never relayed mail! >> >> >> >>Your scanner just thought it did, > > > The "scanner" does not try to interpret any server messages. DSBL only > trusts to real e-mails delivered from your mailserver to DSBL > mailserver. And the explicit evidence is shown in "Messages from this > host" section at http://dsbl.org/listing?212.242.219.138. A test message > relayed from Poland to US via 212.242.219.138. > > >>because of the servers old welcome >>message, which told people that relay is prohibited and reported to >>the police... Now I have removed that message, and tries to remove >>me.. but I can't get the email, because it goes to my ISP... Please >>correct that. > > > To my knowledge, all Mdaemon versions are known to be insecure by > default because of some stable bugs in author's brains. It just trusts > sender's domain in MAIL FROM. Surely, there are semi-documented > workarounds to make it secure; I hope, you have implemented them already. > > Best, > Alexey > DSBL volunteer > > > >> >> >>Med venlig hilsen Brian Kenneth Nielsen >> >> >> >>[email protected] Direct: +45 39 13 02 06 >> >>MONDO A/S Bådehavnsgade 6 DK-2450 København S Tel +45 39 13 02 00 Fax >>+45 39 13 02 01 www.mondo.dk >><file:///D:\Documents%20and%20Settings\jhe.MLAN\Application%20Data\Microsoft\Signatures\www.mondo.dk> >> >> >> >> >> >