OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: Stopping Spam/Virus using fake address' inside local network

From: /dev/rob0 (rob0gmx.co.uk)
Date: Wed Jun 01 2005 - 18:04:07 CDT


Please don't top-post, as it makes the conversation harder to follow.

Mike Burger wrote:
> Might I suggest, instead, that SMTP-AUTH might be a better way to go?
>
> The virii, to date, aren't smart enough to pull the auth info from the
> mail client, so restricting the relay to authenticated users would
> effectively block the virus-generated drek.

Interestingly enough I was just asking about this on SPAM-L earlier
today, and according to a poster there the Sober worm is indeed smart
enough to do this. But even if that's not so, it's only a matter of
time. Nothing but the limitations of the ratware writers would prevent
it: all the MUA settings are in the registry.
--
     mail to this address is discarded unless "/dev/rob0"
     or "not-spam" is in Subject: header