OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Alex van den Bogaerdt (alex_at_ergens.op.HET.NET)
Date: Sun Jul 21 2002 - 17:20:10 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    Victoriano Giralt wrote:

    > > Kinda sounds like what LaBrea (http://www.hackbusters.net/LaBrea/) is
    > > doing but done with a mail server...

    > As Ralf has pointed out, that's tarpitting with a mailserver. A search in

    Technically: No. LaBrea doesn't keep a real connection open and this
    is against the RFCs. Mailservers are expected to wait until the quit
    command is given. Real smpt servers shouldn't fake a connection. They
    *may* deny the connection for policy reasons.

    > Google on that word gives 675 results, the first of which (at least in my
    > search) is a link to a patch for qmail for tarpitting SMTP connections
    > after the 50th RCPT TO: http://www.palomine.net/qmail/tarpit.html

    That would be useful if someone tries to use your server as an open relay
    or when you receive spam for 50+ users at your domain.

    Unless I didn't parse the message correctly, the original intent was to
    tarpit the connection just because the sending host is an open relay,
    right from the start.

    cheers,
    Alex
    -
    To unsubscribe, send mail to majordomopostfix.org with content
    (not subject): unsubscribe postfix-users