OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: reject_unknown_sender_domain - still relevant?
From: Ross Bogue (rbogueentropy.phy.ilstu.edu)
Date: Mon Feb 07 2000 - 11:41:17 CST


At 9:04 AM -0500 2/6/2000, Wietse Venema wrote:
>
>In my case, it is effective and catches a lot of bogus mail.
>
> Wietse

Off-topic, but somewhat related:

What's your current view on TCP Wrapper's "paranoid" setting for
telnet and ftp connections? I don't think it's ever caught a bogus
connection for me. But it has denied access to quite a few students
and faculty whose ISPs leave *many* errors in their DNS files.

A couple of the ISPs fix their typos quickly when I point them out.
But most just ignore my (and their own customers') email. One even
told me that he'd like to fix his problems, but *his* provider (a
national chain) is uncooperative.

I'm leaning toward turning off the "paranoid" setting. I'm not
catching any bad guys, and I am ticking off a bunch of my students
and faculty. I can't even recommend that they switch to different
ISPs, since many of my people live in small farm towns and don't have
another ISP available.

Ross

BTW, is there a version of TCP Wrapper that speaks to AIX's IPv6
implementation yet?

---
Dr. Ross Bogue                          rbogueentropy.phy.ilstu.edu
Physics Department - 4560               Tel: (309) 438-2933
Illinois State University               FAX: (309) 438-5413
Normal, IL 61790