OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: Postfix trying to use invalid IP address...

From: /dev/rob0 (rob0gmx.co.uk)
Date: Fri May 30 2008 - 12:10:29 CDT


On Fri May 30 2008 11:31:02 Dov Oxenberg wrote:
> host ALL returns "ALL.com A 69.50.160.213"
> getent hosts ALL returns "69.50.160.213 ALL.com"

Interesting. Previously this poster had said:

> The only thing in my /etc/resolv.conf is "nameserver 209.51.143.76"

No "search" line. Thus it seems that: 1. either the Debian (? referring
to the original post) C libraries are appending ".com" to unqualified
names (can Debian people test this, please?), or 2. the nameserver at
209.51.143.76 is doing it.

209.51.143.76 is NOT doing that for me. I get NXDOMAIN for "all." Do we
have yet another ill-considered Debian patch in play?

Some notes to the OP:
    1. It worked fine until "all.com." (DNS RR names are case-
       insensitive) started to resolve to an IP address.
    2. REMOVE inet_interfaces, since you want the default setting.
    3. There is nothing in this thread to suggest any compromise or
       intrusion. Stop being so alarmist, you will drive yourself mad.
       *Do* however keep up with your distributor's security patches!
       You're using the "snakeoil[1]" SSL certificate which:
         A. Was generated with a known-insecure openssl library
         B. Is not appropriate for use in the real world.
    4. Your Hotmail Webmail client is horribly mangling the mail we see
       on the list. Try setting it to send plain-text mail only. Also
       consider using a more responsible mail provider.

[1] The name "snakeoil" refers to PRZ's famous PGP readme, and means
    that you are not gaining any security from the misuse of encryption
    technology.
--
    Offlist mail to this address is discarded unless
    "/dev/rob0" or "not-spam" is in Subject: header