OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
RE: reject_unverified_recipient 450 error message exposes VPN addreses

From: Kevin W. Gagel (gagelcnc.bc.ca)
Date: Fri Dec 02 2005 - 13:53:24 CST


>I thought that I had effectively "hidden" the IP address of
>my Windows machine by taking all mention of it out of my MX
>records. Only Postfix itself knows the IP address that mail
>is supposed to be routed to. Although I installed this
>Postfix gateway about six months ago, I am still getting
>hammered with spam sent directly to the addresses on my
>Windows mail server, which bypasses all of my Postfix
>gateway's antispam features. From what I can tell, the ONLY
>way that spammers are able to get the IP address of my
>Windows machine is by getting the information from Postfix
>responses. In effect, a seemingly harmless one-address
>"dictionary attack" gives a spammer all of the info they
>need in order to bypass my Postfix gateway entirely.

The reason you getting spam on your internal is because its
open to the internet. Spammers use scanners to find open
port 25's and send mail to them because they know that
people like you have tried to hide your internal mail server
by not listing it. I doubt very much that they are reading
your non-deliverable reports and working it out from those.

=================================
Kevin W. Gagel
Network Administrator
Information Technology Services
(250) 562-2131 local 448
My Blog:
http://mail.cnc.bc.ca/blogs/gagel

-------------------------------------------------------------------
The College of New Caledonia, Visit us at http://www.cnc.bc.ca
Virus scanning is done on all incoming and outgoing email.
Anti-spam information for CNC can be found at http://avas.cnc.bc.ca
-------------------------------------------------------------------