procmail
[Top] [All Lists]

Re: not sure if this is a sendmail or procmail issue

2003-04-19 07:37:05
Hi

Ok here is a real example. mark(_at_)obantec(_dot_)co(_dot_)uk is a real user 
but from the
header you can see the To: is forged? fake and not a real user. (and the i
have changed the Message-id from my real mailservers name.)

i guess what i am saying is i only want mark(_at_)obantec(_dot_)co(_dot_)uk in 
the To: to be
valid and not work with @mail.obantec.co.uk

Return-Path: <8bmotv(_at_)yahoo(_dot_)com>
Received: from mail.obantec.co.uk ([212.22.95.2])
 by relay.obantec.net (8.12.6/8.12.6) with SMTP id h3JBcO2m004829
 for <mark(_at_)obantec(_dot_)co(_dot_)uk>; Sat, 19 Apr 2003 12:38:25 +0100
Date: Sat, 19 Apr 2003 12:38:24 +0100
Message-Id: 
<200304191138(_dot_)h3JBcO2m004829(_at_)hostname(_dot_)myserver(_dot_)net>
From: "8bmotv(_at_)mail(_dot_)obantec(_dot_)co(_dot_)uk" 
<8bmotv(_at_)mail(_dot_)obantec(_dot_)co(_dot_)uk>
To: Insomn <insomnia(_at_)mail(_dot_)obantec(_dot_)co(_dot_)uk>
Content-type: text/html; charset=koi8-r
Content-Transfer-Encoding: 8bit
Subject: Our sleepless nights...

(oh and yes i will get round to U/G sendmail soon).

Mark

----- Original Message -----
From: "Professional Software Engineering" 
<PSE-L(_at_)mail(_dot_)professional(_dot_)org>
To: <procmail(_at_)lists(_dot_)RWTH-Aachen(_dot_)DE>
Sent: Friday, April 18, 2003 11:56 PM
Subject: Re: not sure if this is a sendmail or procmail issue


At 22:33 2003-04-18 +0100, Obantec Support wrote:
for <localuser(_at_)theirdomain(_dot_)com>;

but a False To: with hostname.myserversdomain.com example

What part of the To: is bogus, and how are you making that
determination?  The username (as per a recent thread here), or that say
the
"hostname" part is not valid?

If the hostname part isn't valid for mail, but is a valid host, you could
reject it at your MTA configuration.  For instance, in the MAILERTABLE
file
(with that option enabled of course), you could set the following
mailertable entry:

bogusmailhost.myserversdomain.com      DISCARD:

I use something similar for the domain used as the envelope address on
some
automated messages my web servers send in response to detecting attacks
from various MS worms - I really don't WANT the bounces for anything that
can't be delivered, and I don't want automated replies to the security
notice either - humans will figure it out easily from the From: address.

i am running sendmail 8.12.8 on RH7.2

You've had nearly 3 weeks to upgrade to 8.12.9.  Get to it.

but not sure how to pass legit localuser(_at_)theirdomain(_dot_)com to their 
mailbox

Uh, you want to BOUNCE the spam after the fact?  Bad idea.  Really bad
idea.

99% of the time, the spam address will be invalid, and that other 1% (or
more, it's growing) will be some poor soul who was targeted by the
spammers
and will be receiving all the bounces and complaints which are generated.

If you're trying to do something else, I clearer example identifying what
part of what actually _varies_ and what is constant, would really help.

---
  Sean B. Straw / Professional Software Engineering

  Procmail disclaimer:
<http://www.professional.org/procmail/disclaimer.html>
  Please DO NOT carbon me on list replies.  I'll get my copy from the
list.


_______________________________________________
procmail mailing list
procmail(_at_)lists(_dot_)RWTH-Aachen(_dot_)DE
http://MailMan.RWTH-Aachen.DE/mailman/listinfo/procmail



_______________________________________________
procmail mailing list
procmail(_at_)lists(_dot_)RWTH-Aachen(_dot_)DE
http://MailMan.RWTH-Aachen.DE/mailman/listinfo/procmail

<Prev in Thread] Current Thread [Next in Thread>