Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > NZ Computing > Mailserver Admin Stupidity

Reply
Thread Tools

Mailserver Admin Stupidity

 
 
Lawrence D'Oliveiro
Guest
Posts: n/a
 
      02-02-2004
In article <bvij0q$3n9$>,
Richard Malcolm-Smith <> wrote:

>And, rejecting based on user gives rise to the rumplestiltskin attacks where
>you know the ones that are delivered because the server doesnt reject the
>recipi[e]nt.


There's an easy solution to that, which Postfix implements by default:
delay some number of seconds before returning the "no such user"
response. That'll make little difference to the delivery of legitimate
mail (invalid users should be rare), but slows down rumpelstiltskin
attacks to the point of uselessness.
 
Reply With Quote
 
 
 
 
Enkidu
Guest
Posts: n/a
 
      02-02-2004
On Mon, 02 Feb 2004 11:27:15 +1300, pbs
<> wrote:

>Richard Malcolm-Smith wrote:
>> Uncle StoatWarbler wrote:
>>
>>> Most systems do that anyway. More to the point they shouldn't be
>>> accepting
>>> mail for any random name in their domain then sending mail later saying
>>> they can't deliver it. Verifying the existance of a local name is trivial
>>> and most MTAs have been doing it for at least a decade.
>>>
>>> Of course the ones which aren't are windows based, or Qmail.

>>
>>
>> Assuming your talking to the server that has details of the users on it,
>> for all you know it may be a backup MX server that will simply relay it
>> to the main mail server when it is available, or else some go between

>
>But when the main mail server is available then it should know if theses
>are legitimate addresses.
>

Many sites (like mine) have a setup where there is an external
mailserver which just sits there and forwards mail through the
firewall. The external mail server does not know whether or not an
email account is valid until it passes the mail through to the
internal mailserver. The internal mail server only accepts mail
relayed by the external mail server.

Cheers,

Cliff
--

I think that Don Brash is a Labour mole.
That would explain everything.
 
Reply With Quote
 
 
 
 
pbs
Guest
Posts: n/a
 
      02-02-2004
Enkidu wrote:
> On Mon, 02 Feb 2004 11:27:15 +1300, pbs
> <> wrote:
>
>
>>Richard Malcolm-Smith wrote:
>>
>>>Uncle StoatWarbler wrote:
>>>
>>>
>>>>Most systems do that anyway. More to the point they shouldn't be
>>>>accepting
>>>>mail for any random name in their domain then sending mail later saying
>>>>they can't deliver it. Verifying the existance of a local name is trivial
>>>>and most MTAs have been doing it for at least a decade.
>>>>
>>>>Of course the ones which aren't are windows based, or Qmail.
>>>
>>>
>>>Assuming your talking to the server that has details of the users on it,
>>>for all you know it may be a backup MX server that will simply relay it
>>>to the main mail server when it is available, or else some go between

>>
>>But when the main mail server is available then it should know if theses
>>are legitimate addresses.
>>

>
> Many sites (like mine) have a setup where there is an external
> mailserver which just sits there and forwards mail through the
> firewall. The external mail server does not know whether or not an
> email account is valid until it passes the mail through to the
> internal mailserver. The internal mail server only accepts mail
> relayed by the external mail server.
>


I agree with you. The internal email, if it is a nice one, will return
emails with invalid addresses to the sender. The external server you
describe is just a relay that stores and forward messages, which is
something email servers do very well. Of course it can not validate user
IDs of a domain or sub-domain too which it is relaying.
 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Urgent : Direct Client is looking for Informatica Admin &Developer(Admin must) sarah Fernandes Java 0 11-01-2010 05:03 PM
Rails: generate scaffold Product Admin overwrites admin pages Phlip Ruby 1 09-15-2006 09:40 PM
OT: Thursday Stupidity Briscobar MCSE 11 06-30-2005 10:28 PM
grasping a Usenet stupidity anthonyberet Computer Support 3 05-28-2004 06:30 AM
FINALLY FIXED (That's to the stupidity on my part) MatGyver Cisco 0 10-29-2003 09:48 PM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57