OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: reject_unverified_recipient 450 error message exposes VPN addreses

From: Ralf Hildebrandt (Ralf.Hildebrandtcharite.de)
Date: Fri Dec 02 2005 - 13:51:45 CST


* William Van Hefner <postmasterthedigest.com>:

> I can give one good example of why this is "giving out too much
> information". In my case, I have Postfix running as a gateway to a
> Windows-based mail server that is on another IP address on the same network.
> Postfix is really just doing scanning for spam and viruses. I have to have
> my Windows mail server on a public IP address, otherwise none of my users
> would be able to access Port 25 to send outbound or access their mail via
> POP (not using the lame Windoze software I am stuck with at the moment, but
> I digress).
>
> I thought that I had effectively "hidden" the IP address of my Windows
> machine by taking all mention of it out of my MX records. Only Postfix
> itself knows the IP address that mail is supposed to be routed to. Although
> I installed this Postfix gateway about six months ago, I am still getting
> hammered with spam sent directly to the addresses on my Windows mail server,
> which bypasses all of my Postfix gateway's antispam features.

A) Why does it accept mail without authoritzation? I mean, your users
   need to use it "to send outbound or access their mail via POP " .. and
   nobody else.

B) You would be amazed, but the net is scanned for machines with an
   open port 25 all the time.

--
Ralf Hildebrandt (Ralf.Hildebrandtcharite.de) spamtrapcharite.de
Postfix - Einrichtung, Betrieb und Wartung Tel. +49 (0)30-450 570-155
http://www.postfix-buch.com
Why you can't find your system administrators:
they're out looking for an ad in any media where DEC mentions OpenVMS