IP address reputation, BorderWare
Kevin Miller
Kevin_Miller at ci.juneau.ak.us
Fri Mar 23 00:03:12 CET 2007
Matt Hampton wrote:
> Chris Yuzik wrote:
>
>> My understanding is that our servers don't do SAV unless the inbound
>> message is for a real recipient (or alias). We prohibit the use of a
>> "catch-all" alias, so a dictionary attack on our server won't really
>> have much effect on you. Or am I wrong (we use SMF-SAV with
>> Sendmail)? If I'm wrong, and the milter initiates a verification
>> even before checking to see if a recipient exists, then I may have
>> to re-evaluate our stance.
>
>
> You are wrong! The standard version does the checks at MAIL FROM
> stage.
>
> I am currently re-writing smf-sav to do exactly what you have
> suggested. It should be completed tommorrow....
>
> Contact me off list if you are interested...
Are you going to let Eugene know - or send the patch back to him?
Perhaps he could make it a configurable option. Simple case statement
and a .conf flag outta be pretty easy to implement.
...Kevin
--
Kevin Miller Registered Linux User No: 307357
CBJ MIS Dept. Network Systems Admin., Mail Admin.
155 South Seward Street ph: (907) 586-0242
Juneau, Alaska 99801 fax: (907 586-4500
More information about the MailScanner
mailing list