<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Realying with sendmail8.11 in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/realying-with-sendmail8-11/m-p/2860132#M820807</link>
    <description>That's not the problem-my relaying is okay but if someone from the outdside pretends to be from the inside mail is accepted.</description>
    <pubDate>Tue, 10 Dec 2002 08:34:44 GMT</pubDate>
    <dc:creator>Lora Ganeva</dc:creator>
    <dc:date>2002-12-10T08:34:44Z</dc:date>
    <item>
      <title>Realying with sendmail8.11</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/realying-with-sendmail8-11/m-p/2860130#M820805</link>
      <description>I have a problem with my mail relay:if anyone pretends to be from a local domain, he could send mail to my local domains:&lt;BR /&gt;for example:&lt;BR /&gt;mail from: kjkjk@btc.bg&lt;BR /&gt;rcpt to: jhjhj@btc.bg&lt;BR /&gt;Message is accepted although the sender is not actually in btc.domain but only pretends to be.</description>
      <pubDate>Mon, 09 Dec 2002 13:56:56 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/realying-with-sendmail8-11/m-p/2860130#M820805</guid>
      <dc:creator>Lora Ganeva</dc:creator>
      <dc:date>2002-12-09T13:56:56Z</dc:date>
    </item>
    <item>
      <title>Re: Realying with sendmail8.11</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/realying-with-sendmail8-11/m-p/2860131#M820806</link>
      <description>Hi,&lt;BR /&gt;Edit /etc/mail/access file,&lt;BR /&gt;CHeck all the RELAY line, and remove unwanted one (like * RELAY),&lt;BR /&gt;Then remap the file :&lt;BR /&gt;makemap -v hash /etc/mail/access if your map is in this format. Or stop/start sendmail ....&lt;BR /&gt;hth&lt;BR /&gt;Benoit&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 09 Dec 2002 16:11:48 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/realying-with-sendmail8-11/m-p/2860131#M820806</guid>
      <dc:creator>benoit Bruckert</dc:creator>
      <dc:date>2002-12-09T16:11:48Z</dc:date>
    </item>
    <item>
      <title>Re: Realying with sendmail8.11</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/realying-with-sendmail8-11/m-p/2860132#M820807</link>
      <description>That's not the problem-my relaying is okay but if someone from the outdside pretends to be from the inside mail is accepted.</description>
      <pubDate>Tue, 10 Dec 2002 08:34:44 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/realying-with-sendmail8-11/m-p/2860132#M820807</guid>
      <dc:creator>Lora Ganeva</dc:creator>
      <dc:date>2002-12-10T08:34:44Z</dc:date>
    </item>
    <item>
      <title>Re: Realying with sendmail8.11</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/realying-with-sendmail8-11/m-p/2860133#M820808</link>
      <description>Hi,&lt;BR /&gt;In access file, the "name" check the link with IP address, and if the ip address is not from your network, then you cannot send mail. You cazn easily pretend you are from a local domain with smtp commands, but it's more difficult to spoof an address&lt;BR /&gt;If you try by hand trough telnet 25 :&lt;BR /&gt;Make the test from an internal IP address, you can send...&lt;BR /&gt;Then try a telnet 25 to your HP frame from an internet connection, and test it . If relay is denied, then you cannot send mail.&lt;BR /&gt;&lt;BR /&gt;hth&lt;BR /&gt;Benoit&lt;BR /&gt;_________&lt;BR /&gt;"L'art d'??crire pr??c??de la pens??e."&lt;BR /&gt;Emile Chartier, dit Alain, Propos de litt??rature&lt;BR /&gt;</description>
      <pubDate>Tue, 10 Dec 2002 09:26:30 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/realying-with-sendmail8-11/m-p/2860133#M820808</guid>
      <dc:creator>benoit Bruckert</dc:creator>
      <dc:date>2002-12-10T09:26:30Z</dc:date>
    </item>
    <item>
      <title>Re: Realying with sendmail8.11</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/realying-with-sendmail8-11/m-p/2860134#M820809</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;you cannot just block the mail with sender domain btc.org. Then your mail relay will not accept mails from internal servers to relay.&lt;BR /&gt;&lt;BR /&gt;What is needed is rule in sendmail filters like milter etc.&lt;BR /&gt;&lt;BR /&gt;sender address: *@btc.org&lt;BR /&gt;destination address: *@btc.org&lt;BR /&gt;Action: REJECT&lt;BR /&gt;&lt;BR /&gt;regards,&lt;BR /&gt;U.SivaKumar&lt;BR /&gt;</description>
      <pubDate>Tue, 10 Dec 2002 12:07:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/realying-with-sendmail8-11/m-p/2860134#M820809</guid>
      <dc:creator>U.SivaKumar_2</dc:creator>
      <dc:date>2002-12-10T12:07:21Z</dc:date>
    </item>
    <item>
      <title>Re: Realying with sendmail8.11</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/realying-with-sendmail8-11/m-p/2860135#M820810</link>
      <description>I have tried and the message was accepted, I tried form an ioutside host pretending to be from inside</description>
      <pubDate>Tue, 10 Dec 2002 12:23:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/realying-with-sendmail8-11/m-p/2860135#M820810</guid>
      <dc:creator>Lora Ganeva</dc:creator>
      <dc:date>2002-12-10T12:23:04Z</dc:date>
    </item>
    <item>
      <title>Re: Realying with sendmail8.11</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/realying-with-sendmail8-11/m-p/2860136#M820811</link>
      <description>I made a check,&lt;BR /&gt;And to deny relaying you have also to define the relay-domains ;&lt;BR /&gt;in sendmail.cf :&lt;BR /&gt;FR-o /etc/mail/relay-domains&lt;BR /&gt;&lt;BR /&gt;And in this file, you specify the name (DNS) of the network for which you accept relay...or only hosts, or anything...&lt;BR /&gt;&lt;BR /&gt;Can you make the test with this file to check relay..&lt;BR /&gt;By default relay is denied in sendmail 8.11, I think you should have comment something in the sendmail.cf to disable it !!&lt;BR /&gt;&lt;BR /&gt;hth&lt;BR /&gt;Benoit&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 10 Dec 2002 13:06:17 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/realying-with-sendmail8-11/m-p/2860136#M820811</guid>
      <dc:creator>benoit Bruckert</dc:creator>
      <dc:date>2002-12-10T13:06:17Z</dc:date>
    </item>
    <item>
      <title>Re: Realying with sendmail8.11</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/realying-with-sendmail8-11/m-p/2860137#M820812</link>
      <description>I have tried this but it doesn't work..sorry</description>
      <pubDate>Wed, 11 Dec 2002 13:07:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/realying-with-sendmail8-11/m-p/2860137#M820812</guid>
      <dc:creator>Lora Ganeva</dc:creator>
      <dc:date>2002-12-11T13:07:19Z</dc:date>
    </item>
    <item>
      <title>Re: Realying with sendmail8.11</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/realying-with-sendmail8-11/m-p/2860138#M820813</link>
      <description>When relaying mail, an appropriately configured sendmail will verify that a sender's domain (e.g. btc.bg) exists and looks up in DNS, but sendmail will _not_ verify that the actual account exists.&lt;BR /&gt;&lt;BR /&gt;If sendmail thinks btc.bg is local, sendmail won't pass the mail through the relay rulesets (since the mail is local), so the access database isn't in play, per se.  sendmail _might_ verify that the recipient address exists, depending on your configuration.&lt;BR /&gt;&lt;BR /&gt;Users can set the From: address to be just about anything with little ramification, unless&lt;BR /&gt;1) the domain of the sender doesn't exist&lt;BR /&gt;or&lt;BR /&gt;2) the domain of the sender (and the client IP/domain) isn't consider local, and the recipient address isn't considered local (e.g. relay.&lt;BR /&gt;&lt;BR /&gt;In the case of #2, modern versions of sendmail require that relaying be specifically enabled - relaying is off by default.  You use the access database to control relaying.&lt;BR /&gt;</description>
      <pubDate>Wed, 11 Dec 2002 13:18:31 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/realying-with-sendmail8-11/m-p/2860138#M820813</guid>
      <dc:creator>Christopher Caldwell</dc:creator>
      <dc:date>2002-12-11T13:18:31Z</dc:date>
    </item>
    <item>
      <title>Re: Realying with sendmail8.11</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/realying-with-sendmail8-11/m-p/2860139#M820814</link>
      <description>Hi,&lt;BR /&gt;Christopher gave the proper answer, about relaying, and sendmail 8.11 should deny relay by default !!&lt;BR /&gt;I think that the best thing to do is to start from nothing with sendmail and build your config !&lt;BR /&gt;You can do that from sources, or from a binary. In the last case, I don't know if the anti relay is enable or not !! (it's just an sendmail.cf config !!)&lt;BR /&gt;From sources, there's a cf /cf subdirectory with mc files that you can use to build the cf ! (It's the best way.)&lt;BR /&gt;hth&lt;BR /&gt;Benoit</description>
      <pubDate>Wed, 11 Dec 2002 14:05:47 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/realying-with-sendmail8-11/m-p/2860139#M820814</guid>
      <dc:creator>benoit Bruckert</dc:creator>
      <dc:date>2002-12-11T14:05:47Z</dc:date>
    </item>
    <item>
      <title>Re: Realying with sendmail8.11</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/realying-with-sendmail8-11/m-p/2860140#M820815</link>
      <description>The problem is not relaying..as I say.</description>
      <pubDate>Wed, 11 Dec 2002 14:20:45 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/realying-with-sendmail8-11/m-p/2860140#M820815</guid>
      <dc:creator>Lora Ganeva</dc:creator>
      <dc:date>2002-12-11T14:20:45Z</dc:date>
    </item>
    <item>
      <title>Re: Realying with sendmail8.11</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/realying-with-sendmail8-11/m-p/2860141#M820816</link>
      <description>You are right Lora,&lt;BR /&gt;I've read again this thread and the trouble question is that the rcpt to is going to the same domain as the from.&lt;BR /&gt;I.E. anti relay works when you do somthing like that :&lt;BR /&gt;mail from:dddd@btc.com &lt;BR /&gt;rcpt to :dddd@otherdomain.com&lt;BR /&gt;For your, the rcpt is OK, then no anti relay mechanism is working.&lt;BR /&gt;I.E.&lt;BR /&gt;You receive an email from otherdomain to your domain (standard behavior) &lt;BR /&gt;mail from ddd@otherdomain.com&lt;BR /&gt;rcpt to:ddd@btc.com&lt;BR /&gt;In this case it works, by default sendmail doesn't make any check on the ip address of the sender. By the way it's possible to place any sender domain.&lt;BR /&gt;Some smtp products add the control with a reverse lookup of the ip address of the sender in order to test if the from sender domain is the sam e as the IP !!!&lt;BR /&gt;But by this way a lot of mails will be stopped because many domains doesn't registered the reverse lookup, or the sender (legal one) may use a backup line from aonther provider with of course another ip not linked with the domain !!! &lt;BR /&gt;I don't know how to activate it in  sendmail : &lt;BR /&gt;See may be &lt;BR /&gt;FEATURE(relay_based_on_MX)&lt;BR /&gt;&lt;BR /&gt;And also U.SHIVA proposal  could be used...&lt;BR /&gt;Sorry to not give a better answer and all the time lost because I didn't read properly your first post !&lt;BR /&gt;&lt;BR /&gt;hth&lt;BR /&gt;Benoit&lt;BR /&gt;</description>
      <pubDate>Wed, 11 Dec 2002 14:47:31 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/realying-with-sendmail8-11/m-p/2860141#M820816</guid>
      <dc:creator>benoit Bruckert</dc:creator>
      <dc:date>2002-12-11T14:47:31Z</dc:date>
    </item>
    <item>
      <title>Re: Realying with sendmail8.11</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/realying-with-sendmail8-11/m-p/2860142#M820817</link>
      <description>&amp;gt; The problem is not relaying..as I say. &lt;BR /&gt;&lt;BR /&gt;Right - you aren't hitting the relay rulesets, so sendmail doesn't examine the from address at all&lt;BR /&gt;&lt;BR /&gt;_and_&lt;BR /&gt;&lt;BR /&gt;even if you where hitting the relay rulesets, (if you've go this turned on) sendmail only verifies that the domain porition of the From address looks up in DNS (i.e. returns an MX) -- sendmail doesn't care user part of the address.</description>
      <pubDate>Wed, 11 Dec 2002 15:30:48 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/realying-with-sendmail8-11/m-p/2860142#M820817</guid>
      <dc:creator>Christopher Caldwell</dc:creator>
      <dc:date>2002-12-11T15:30:48Z</dc:date>
    </item>
  </channel>
</rss>

