IP address reputation, BorderWare

Kevin Miller Kevin_Miller at ci.juneau.ak.us
Fri Mar 23 00:03:12 CET 2007


Matt Hampton wrote:
> Chris Yuzik wrote:
> 
>> My understanding is that our servers don't do SAV unless the inbound
>> message is for a real recipient (or alias). We prohibit the use of a
>> "catch-all" alias, so a dictionary attack on our server won't really
>> have much effect on you. Or am I wrong (we use SMF-SAV with
>> Sendmail)? If I'm wrong, and the milter initiates a verification
>> even before checking to see if a recipient exists, then I may have
>> to re-evaluate our stance.
> 
> 
> You are wrong! The standard version does the checks at MAIL FROM
> stage. 
> 
> I am currently re-writing smf-sav to do exactly what you have
>   suggested. It should be completed tommorrow....
> 
> Contact me off list if you are interested...

Are you going to let Eugene know - or send the patch back to him?
Perhaps he could make it a configurable option.  Simple case statement
and a .conf flag outta be pretty easy to implement.

...Kevin
-- 
Kevin Miller                Registered Linux User No: 307357
CBJ MIS Dept.               Network Systems Admin., Mail Admin.
155 South Seward Street     ph: (907) 586-0242
Juneau, Alaska 99801        fax: (907 586-4500


More information about the MailScanner mailing list