OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: .exe, and other attachments

From: Tony Earnshaw (tonnibilly.demon.nl)
Date: Thu Sep 25 2003 - 07:36:52 CDT


Jim Seymour wrote:

> The future is here. Swen does indeed go through the sender's
> designated mail server. The good news is: Word has it the envelope
> sender is valid. From the looks of my rejects, that may well be the
> case, as, with few exceptions, the envelope sender address is
> consistent with the SMTP client's domain.

In my experience, all Swen stuff comes with genuine envelope sender.
Being a modem user and with a mail volume that's easy to manage, that's
how I'm blocking it - I block off 95% of TLD envelope sender domains to
begin with and make exceptions for the goodies. You'd be surprised at
how many TLDs there are. I just allowed through 71 genuine mails and
rejected 327 that way, amavisd-new dealt with 12 .exes that slipped
through (just costs me extra connection time). Not one made it through
to me. In this respect, pflogsumm is a true blessing; renewed thanks
from a grateful user ;)

> So, with any luck, the people getting the bounces are the lusers that
> executed the thing.

Right. They're all getting "Access denied" from me, but looking at some
of the luser addresses, I doubt whether they'll understand. "I never
sent him any mail, I don't even know him, forget it". Though if enough
people are doing it, i suppose the penny might drop.

--Tonni

--
Tony Earnshaw

Millom kaksar eg litet kann trivast, millom jamningar helst er eg nøgd

http://www.billy.demon.nl
Mail: tonnibilly.demon.nl