[ale] Strange sendmail (and postfix) spam issue: accepting fail "from" myself?

Derek Atkins warlord at MIT.EDU
Wed Mar 30 10:26:12 EDT 2016


Alex Carver <agcarver+ale at acarver.net> writes:

> On 2016-03-29 12:04, Derek Atkins wrote:
>
>>> Alternatively set up a rule that if the from domain matches yours, it
>>> must also match your IP address.
>> 
>> This is something I'd love.  So, how do I so this in sendmail-speak?
>> I've spent too much time googling and haven't found a macro that does it,
>> and honestly these days my sendmail config fu is based on what's in the
>> .m4 macro documentation.  :(
>
> I wouldn't have expected v6 to matter.  It's just rDNS so if that's not
> set up then that's the remote side's fault.

While I agree in principle, the end users are the ones that were
affected.  So I had to turn off that protection.

> As for the rule, no clue how to write it in sendmail's m4 macros, I use
> exim for the MTA.

Oh.  :(

Any sendmail guys here?

-derek

PS: It does look like this particular attack vector has slowed down.
But I'd like to stop it completely for the future, if possible.

-- 
       Derek Atkins, SB '93 MIT EE, SM '95 MIT Media Laboratory
       Member, MIT Student Information Processing Board  (SIPB)
       URL: http://web.mit.edu/warlord/    PP-ASEL-IA     N1NWH
       warlord at MIT.EDU                        PGP key available


More information about the Ale mailing list