OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: smtpd_reject_unlisted_recipient

From: Sahil Tandon (sahilFreeBSD.org)
Date: Thu Jun 10 2010 - 19:49:40 CDT


On Thu, 10 Jun 2010, Jerrale Gayle wrote:

> On 6/10/2010 6:31 PM, Sahil Tandon wrote:
> >On Thu, 10 Jun 2010, Jerrale Gayle wrote:
> >
> >>smtpd_reject_unlisted_recipient = no
> >Bad idea.
> >
> >>Would this be better put by itself or under
> >>smtpd_recipient_restrictions = reject_unlisted_recipient=no?
> >Bad idea + unsupported syntax.
> >
> >>I want to accept all mail to non-existent users, then bounce, so
> >>that people can't probe for valid users to know wherer to start a
> >>brute force.
> >This is a horrible idea; please do not do this. Google 'backscatter'.
> >
> IF I have repeating undeliverable mail being redirected to
> postmastermydomain, I don't see why this would be a bad idea.

This is my last reply on this topic; from wikipedia:

Backscatter occurs because worms and spam messages often forge their
sender address, and mailservers configured by naive administrators send
a bounce message to this address.

--
Sahil Tandon <sahilFreeBSD.org>