OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: the purpose of smtpd_sasl_authenticated_header

From: Ralf Hildebrandt (Ralf.Hildebrandtcharite.de)
Date: Tue May 02 2006 - 14:35:21 CDT


* Udo Rader <udo.raderbestsolution.at>:
> Hi,
>
> as we are currently testing 2.3 I would like to know the rationale
> behind smtpd_sasl_authenticated_header.
>
> On one hand I find the flag useful for tracing purposes, but on the
> other hand I already see hordes of script kiddies/spammers harvesting
> the login names for brute force attacks.
>
> So what's the idea behind it?

# postconf -d smtpd_sasl_authenticated_header
smtpd_sasl_authenticated_header = no

The idea is to activate it if YOU think it's useful.

--
Ralf Hildebrandt (Ralf.Hildebrandtcharite.de) spamtrapcharite.de
Postfix - Einrichtung, Betrieb und Wartung Tel. +49 (0)30-450 570-155
http://www.postfix-buch.com
First Law of System Requirements:
   "Anything is possible if you don't know what you're talking about..."