OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: strange order of log entries

From: Alexey Lobanov (A.Lobanovcro-rct.ru)
Date: Thu Feb 14 2008 - 07:58:12 CST


Hello.

14.02.2008 16:26, Ralf Hildebrandt пишет:

> * Alexey Lobanov <A.Lobanovcro-rct.ru>:
>
>> Just a thought. In my experience. Postfix 2.4 has perfectly working
>> milter interface. amavisd-milter sees to be stable enough too. And all
>> those "reinjections" are known as a major source of bugs including
>> open-relay vulnerabilities.
>
> Open relay on localhost?

Similar antivirus "chains" are sometimes fooled by source-routing, uucp
notation and other old plain addressing tricks. At the first stage the
message is accepted as locally destinated, at the second stage it
becomes locally originated and is properly routed to the remote destination.

Of course, I don't say that this specific setup is vulnerable. But the
milter model seems to be more transparent and predictable.

Alexey