<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Sendmail config in Operating System - Linux</title>
    <link>https://community.hpe.com/t5/operating-system-linux/sendmail-config/m-p/3183185#M9596</link>
    <description>Sendmail seems to be relaying.  I'm using the default setup from RedHat 7.1 installed on HP 8500 running Apache server. I enabled FEATURE(redirect) so that /etc/aliases would work but don't want to do relaying for just anybody.&lt;BR /&gt;&lt;BR /&gt;I think I might be relaying because maillog gets about a thousand relay= entries a day like the example below:&lt;BR /&gt;&lt;BR /&gt;Feb  1 05:16:32 linda sendmail[1941]: i11BGMq01941: from=&lt;LINDA&gt;,&lt;BR /&gt;size=0, class=0, nrcpts=0, proto=ESMTP, daemon=MTA, relay=h24-68-12-216.gv.shawcable.net [24.68.12.216]&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Any ideas ??&lt;/LINDA&gt;</description>
    <pubDate>Wed, 04 Feb 2004 15:21:31 GMT</pubDate>
    <dc:creator>Vernon Brown_4</dc:creator>
    <dc:date>2004-02-04T15:21:31Z</dc:date>
    <item>
      <title>Sendmail config</title>
      <link>https://community.hpe.com/t5/operating-system-linux/sendmail-config/m-p/3183185#M9596</link>
      <description>Sendmail seems to be relaying.  I'm using the default setup from RedHat 7.1 installed on HP 8500 running Apache server. I enabled FEATURE(redirect) so that /etc/aliases would work but don't want to do relaying for just anybody.&lt;BR /&gt;&lt;BR /&gt;I think I might be relaying because maillog gets about a thousand relay= entries a day like the example below:&lt;BR /&gt;&lt;BR /&gt;Feb  1 05:16:32 linda sendmail[1941]: i11BGMq01941: from=&lt;LINDA&gt;,&lt;BR /&gt;size=0, class=0, nrcpts=0, proto=ESMTP, daemon=MTA, relay=h24-68-12-216.gv.shawcable.net [24.68.12.216]&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Any ideas ??&lt;/LINDA&gt;</description>
      <pubDate>Wed, 04 Feb 2004 15:21:31 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/sendmail-config/m-p/3183185#M9596</guid>
      <dc:creator>Vernon Brown_4</dc:creator>
      <dc:date>2004-02-04T15:21:31Z</dc:date>
    </item>
    <item>
      <title>Re: Sendmail config</title>
      <link>https://community.hpe.com/t5/operating-system-linux/sendmail-config/m-p/3183186#M9597</link>
      <description>Vernon,&lt;BR /&gt;&lt;BR /&gt;I've been dealin with this myself. Checklist:&lt;BR /&gt;&lt;BR /&gt;/etc/mail/access&lt;BR /&gt;&lt;BR /&gt;Only local IP addresses on your internal network should be set to RELAY. Even if you host internet domains, you don't need RELAY on the subdomains.&lt;BR /&gt;&lt;BR /&gt;I'm attaching my buildmail script which will build the hast databases.&lt;BR /&gt;&lt;BR /&gt;In all documentroot and subdirectories you need a robots.txt file. That file prevents external users from using your cgi formscripts to relay mail&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;See these threads:&lt;BR /&gt;&lt;A href="http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=333766" target="_blank"&gt;http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=333766&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=358250" target="_blank"&gt;http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=358250&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=250630" target="_blank"&gt;http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=250630&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=391433" target="_blank"&gt;http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=391433&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Just because these threads are hpux does not invalidate them. Sendmail is sendmail.&lt;BR /&gt;&lt;BR /&gt;Also, if you suspect formscripts, do a google search for Fromscript security&lt;BR /&gt;&lt;BR /&gt;Your scripts can be used to relay mail.&lt;BR /&gt;&lt;BR /&gt;SEP&lt;BR /&gt;&lt;BR /&gt;Need more? Just ask.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 04 Feb 2004 15:28:09 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/sendmail-config/m-p/3183186#M9597</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2004-02-04T15:28:09Z</dc:date>
    </item>
    <item>
      <title>Re: Sendmail config</title>
      <link>https://community.hpe.com/t5/operating-system-linux/sendmail-config/m-p/3183187#M9598</link>
      <description>Vhat happened to my attachment?????&lt;BR /&gt;&lt;BR /&gt;Trying again.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Wed, 04 Feb 2004 15:30:30 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/sendmail-config/m-p/3183187#M9598</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2004-02-04T15:30:30Z</dc:date>
    </item>
    <item>
      <title>Re: Sendmail config</title>
      <link>https://community.hpe.com/t5/operating-system-linux/sendmail-config/m-p/3183188#M9599</link>
      <description>By default your sendmail shouldn't permit relay ( from 8.9 version of sendmail)&lt;BR /&gt;&lt;BR /&gt;for start edit the file /etc/mail/relay-domains  for relay permited domains entries.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 04 Feb 2004 15:33:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/sendmail-config/m-p/3183188#M9599</guid>
      <dc:creator>Alexander Chuzhoy</dc:creator>
      <dc:date>2004-02-04T15:33:25Z</dc:date>
    </item>
    <item>
      <title>Re: Sendmail config</title>
      <link>https://community.hpe.com/t5/operating-system-linux/sendmail-config/m-p/3183189#M9600</link>
      <description>I found an open-relay test site in one of Steven's examples. 14 tests came back; "relaying denied"&lt;BR /&gt;&lt;BR /&gt;Yet I'm getting all these log file hits. I don't see any indication in the log entries that the relay was blocked ??&lt;BR /&gt;&lt;BR /&gt;Is there any way to tell if the log entries are the result of successful relays ?&lt;BR /&gt;&lt;BR /&gt;Thanks for your input !!</description>
      <pubDate>Wed, 04 Feb 2004 17:17:51 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/sendmail-config/m-p/3183189#M9600</guid>
      <dc:creator>Vernon Brown_4</dc:creator>
      <dc:date>2004-02-04T17:17:51Z</dc:date>
    </item>
    <item>
      <title>Re: Sendmail config</title>
      <link>https://community.hpe.com/t5/operating-system-linux/sendmail-config/m-p/3183190#M9601</link>
      <description>Those log entries are probably the result of successful relays.&lt;BR /&gt;&lt;BR /&gt;I've put together a package of scripts for you that I use on Linux to scan my logs and such for possible spam.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.isnamerica.com/spam.tar.gz" target="_blank"&gt;http://www.isnamerica.com/spam.tar.gz&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;It also includes my spammer list and access configuration as a referendce. Let me know when its downloaded because I'm going to remove it.&lt;BR /&gt;&lt;BR /&gt;spamlist lets me forward via elm spam messages to me and then process them into /etc/access blocks.&lt;BR /&gt;&lt;BR /&gt;SEP&lt;BR /&gt;</description>
      <pubDate>Wed, 04 Feb 2004 17:26:39 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/sendmail-config/m-p/3183190#M9601</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2004-02-04T17:26:39Z</dc:date>
    </item>
    <item>
      <title>Re: Sendmail config</title>
      <link>https://community.hpe.com/t5/operating-system-linux/sendmail-config/m-p/3183191#M9602</link>
      <description>Thanks Steven; I have downloaded the file.&lt;BR /&gt;&lt;BR /&gt;I'll play around with it and try to put it to work !1</description>
      <pubDate>Wed, 04 Feb 2004 18:13:56 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/sendmail-config/m-p/3183191#M9602</guid>
      <dc:creator>Vernon Brown_4</dc:creator>
      <dc:date>2004-02-04T18:13:56Z</dc:date>
    </item>
    <item>
      <title>Re: Sendmail config</title>
      <link>https://community.hpe.com/t5/operating-system-linux/sendmail-config/m-p/3183192#M9603</link>
      <description>Vernon,&lt;BR /&gt;&lt;BR /&gt;While trying to help you with your issue, my server was attacked with a relay attack.&lt;BR /&gt;&lt;BR /&gt;This does not mean you should not do what I've advised. But in a very painful two hour period I have learned more.&lt;BR /&gt;&lt;BR /&gt;If you have cgi formscripts, you need this code near the top:&lt;BR /&gt;&lt;BR /&gt;@referers = ('67.94.143.147','67.94.143.147');&lt;BR /&gt;@recipients = ('yourname@yourdomain.com');&lt;BR /&gt;&lt;BR /&gt;You may need this depending on what kind of form you are using:&lt;BR /&gt;&lt;BR /&gt;if ( $sender ne "yourname\@yourdomain.com" )&lt;BR /&gt;{&lt;BR /&gt; print "Content-type: text/html\r\n\r\n";&lt;BR /&gt; print "&lt;H1&gt;&lt;CENTER&gt; Hijacking of scripts is ILLEGAL!&lt;BR /&gt; Your&lt;BR /&gt; ip address, $ENV{'REMOTE_ADDR'} has been recorded, as&lt;BR /&gt; &lt;BR /&gt; as well as the date and time.&lt;BR /&gt;$refer&lt;BR /&gt;$ENV{'HTTP_REFERER'}&lt;/CENTER&gt; &lt;/H1&gt;";&lt;BR /&gt;  exit(0);&lt;BR /&gt;}&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;This code is a retrofit for formmail scripts that lets you stop people from using your scripts to send their mail.&lt;BR /&gt;&lt;BR /&gt;I've come pretty close to closing all the holes, so when the attacker found a weak script he/she/it queued up a bunch of mail for later delivery.&lt;BR /&gt;&lt;BR /&gt;mailq spots it&lt;BR /&gt;&lt;BR /&gt;rm -f /var/spool/mqueue/*&lt;BR /&gt;&lt;BR /&gt;Will clean out the mail queue. Good mail as well as bad will die an untimely death.&lt;BR /&gt;&lt;BR /&gt;I actually saw messages queued up to go to aol.com scheduled for the next 24 hours.&lt;BR /&gt;&lt;BR /&gt;Also, here is the code of robots.txt&lt;BR /&gt;&lt;BR /&gt;It should keep folks out of your cgi-bin directory.&lt;BR /&gt;&lt;BR /&gt;User-agent: *&lt;BR /&gt;Disallow: /cgi-bin&lt;BR /&gt;Disallow: /server-cgi&lt;BR /&gt;Disallow: /images&lt;BR /&gt;&lt;BR /&gt;#&lt;BR /&gt;# Standard robot exclusion entries- PLEASE DO NOT DELETE!&lt;BR /&gt;#&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;We should exchange notes and help each other on this issue. You may have been exploited in a way that I don't know about.&lt;BR /&gt;&lt;BR /&gt;I will keep up my end and feel free to update me with anything you discover.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Wed, 04 Feb 2004 21:52:07 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/sendmail-config/m-p/3183192#M9603</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2004-02-04T21:52:07Z</dc:date>
    </item>
    <item>
      <title>Re: Sendmail config</title>
      <link>https://community.hpe.com/t5/operating-system-linux/sendmail-config/m-p/3183193#M9604</link>
      <description>Thanks for the info Steven; I've also been getting new scans looking for valid users on my servers. Example:&lt;BR /&gt;&lt;BR /&gt;Feb  4 01:03:25 linda sendmail[6297]: i1473OO06297: &lt;ALICE&gt;... User unknown&lt;BR /&gt;Feb  4 01:06:32 linda sendmail[6299]: i1476VO06299: &lt;TOM&gt;... User unknown&lt;BR /&gt;Feb  4 01:06:39 linda sendmail[6301]: i1476bO06301: &lt;TOM&gt;... User unknown&lt;BR /&gt;Feb  4 01:06:42 linda sendmail[6303]: i1476gO06303: &lt;JACK&gt;... User unknown&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;This is from the maillog. Seems to be someone scanning for valid users. So far they haven't found any but they eventually will. Now the question; what will they do when they know a vaild user name ??&lt;BR /&gt;&lt;BR /&gt;Interesting ! I'll follow up on this. I will keep in touch. Thanks for all your help !&lt;BR /&gt;&lt;BR /&gt;Vern&lt;/JACK&gt;&lt;/TOM&gt;&lt;/TOM&gt;&lt;/ALICE&gt;</description>
      <pubDate>Wed, 04 Feb 2004 23:37:35 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/sendmail-config/m-p/3183193#M9604</guid>
      <dc:creator>Vernon Brown_4</dc:creator>
      <dc:date>2004-02-04T23:37:35Z</dc:date>
    </item>
    <item>
      <title>Re: Sendmail config</title>
      <link>https://community.hpe.com/t5/operating-system-linux/sendmail-config/m-p/3183194#M9605</link>
      <description>Does a thousand combined incoming and outgoing messages a day sound reasonable for your server?  That may just be your normal load.&lt;BR /&gt;&lt;BR /&gt;Check the full trace for this message.  Look for the other entries in the log that contain "i11BGMq01941" and you'll get the full picture of what this message was doing.&lt;BR /&gt;&lt;BR /&gt;The "relay=" on the line may be nothing because it's put on every line that has "from=" on it so you know what machine actually sent (relayed) the message to you.&lt;BR /&gt;&lt;BR /&gt;In the example you gave, "linda@earhling.net" sent a message and it hit your server from the machine "h24-68-12-216.gv.shawcable.net".  To know more, you need to look at the rest of the log entries.&lt;BR /&gt;&lt;BR /&gt;If the entry that has "to=" is someone in your domain, everything's fine.  If it's for someone outside your domain, you've got a problem.&lt;BR /&gt;&lt;BR /&gt;With the open relay checks you ran, it sounds like you're not relaying, but check it out just in case.&lt;BR /&gt;&lt;BR /&gt;You can see what normal messages look like in the logs by sending one to someone you know and tracking that.  Then have someone send one to you and track it.  That'll give you an idea of what you're looking at.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Seth</description>
      <pubDate>Thu, 05 Feb 2004 00:15:24 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/sendmail-config/m-p/3183194#M9605</guid>
      <dc:creator>Seth Parker</dc:creator>
      <dc:date>2004-02-05T00:15:24Z</dc:date>
    </item>
    <item>
      <title>Re: Sendmail config</title>
      <link>https://community.hpe.com/t5/operating-system-linux/sendmail-config/m-p/3183195#M9606</link>
      <description>I'm attaching my sendmail.mc which I use with the prevoiusly submitted buildmail script.&lt;BR /&gt;&lt;BR /&gt;It sets sendmail to not accept these kind of probes.&lt;BR /&gt;&lt;BR /&gt;If that does not work, run Bastille on your system and answer the sendmail questions Yes.&lt;BR /&gt;&lt;BR /&gt;That will stop people from doing that.&lt;BR /&gt;&lt;BR /&gt;The scan you see if people trying to find valid  users they can spam.&lt;BR /&gt;&lt;BR /&gt;They can use these users to send you spam and cc others. Bad.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Thu, 05 Feb 2004 00:21:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/sendmail-config/m-p/3183195#M9606</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2004-02-05T00:21:13Z</dc:date>
    </item>
    <item>
      <title>Re: Sendmail config</title>
      <link>https://community.hpe.com/t5/operating-system-linux/sendmail-config/m-p/3183196#M9607</link>
      <description>the best test to check your if your server allows relay is here:&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt; &lt;A href="http://abuse.net/relay.html" target="_blank"&gt;http://abuse.net/relay.html&lt;/A&gt;</description>
      <pubDate>Thu, 05 Feb 2004 01:43:26 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/sendmail-config/m-p/3183196#M9607</guid>
      <dc:creator>Alexander Chuzhoy</dc:creator>
      <dc:date>2004-02-05T01:43:26Z</dc:date>
    </item>
    <item>
      <title>Re: Sendmail config</title>
      <link>https://community.hpe.com/t5/operating-system-linux/sendmail-config/m-p/3183197#M9608</link>
      <description>I think the site posted is great btw.  My server passed all the relay tests. It does not test cgi form abuse.&lt;BR /&gt;&lt;BR /&gt;my google search on that topic:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.google.com/search?hl=en&amp;amp;ie=UTF-8&amp;amp;oe=UTF-8&amp;amp;q=Formmail+security&amp;amp;btnG=Google+Search" target="_blank"&gt;http://www.google.com/search?hl=en&amp;amp;ie=UTF-8&amp;amp;oe=UTF-8&amp;amp;q=Formmail+security&amp;amp;btnG=Google+Search&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;This one is really good.&lt;BR /&gt;&lt;A href="http://216.239.39.104/search?q=cache:Wx8Se0MeqD0J:www.monkeys.com/anti-spam/formmail-advisory.pdf+Formmail+security&amp;amp;hl=en&amp;amp;ie=UTF-8" target="_blank"&gt;http://216.239.39.104/search?q=cache:Wx8Se0MeqD0J:www.monkeys.com/anti-spam/formmail-advisory.pdf+Formmail+security&amp;amp;hl=en&amp;amp;ie=UTF-8&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Finally, it took an hour to put this all together will all the interupts, you should test your own site from outside with the following scripts:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.yoursite.com/cgi-bin/formmail.cgi?recipient=email@poorspamrecipient.com&amp;amp;message=You" target="_blank"&gt;http://www.yoursite.com/cgi-bin/formmail.cgi?recipient=email@poorspamrecipient.com&amp;amp;message=You&lt;/A&gt;  have been spammed&lt;BR /&gt;&lt;BR /&gt;If the mail gets through, you have a problem.&lt;BR /&gt;&lt;BR /&gt;SEP&lt;BR /&gt;</description>
      <pubDate>Thu, 05 Feb 2004 02:41:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/sendmail-config/m-p/3183197#M9608</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2004-02-05T02:41:16Z</dc:date>
    </item>
    <item>
      <title>Re: Sendmail config</title>
      <link>https://community.hpe.com/t5/operating-system-linux/sendmail-config/m-p/3183198#M9609</link>
      <description>Thanks Alexander; tried it; passed all the tests. Still getting the log entries.&lt;BR /&gt;&lt;BR /&gt;I've tried tweaking the log level to make it show more info. Still need something in the log entry to say if the transaction was successful or was blocked !&lt;BR /&gt;&lt;BR /&gt;Strange that this most important info would not be in the log entry.&lt;BR /&gt;&lt;BR /&gt;Steven; I did have the problem of spammers using formmail. I finally changed the name of formmail which I could do since I had control of all the legal scripts that used it. I scan daily for abuse of that; get lots of attempts;  no successes.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 05 Feb 2004 08:51:43 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/sendmail-config/m-p/3183198#M9609</guid>
      <dc:creator>Vernon Brown_4</dc:creator>
      <dc:date>2004-02-05T08:51:43Z</dc:date>
    </item>
    <item>
      <title>Re: Sendmail config</title>
      <link>https://community.hpe.com/t5/operating-system-linux/sendmail-config/m-p/3183199#M9610</link>
      <description>Vernon,&lt;BR /&gt;&lt;BR /&gt;I have some excellent news for you:&lt;BR /&gt;&lt;BR /&gt;The changes I recommended in the formscripts worked really well.&lt;BR /&gt;&lt;BR /&gt;An attempt was made to send about 50,000 messages through my server in 500 message batches.&lt;BR /&gt;&lt;BR /&gt;The nasty little spammer thought he/she/it was getting aol. All messages were limited by their recipient base to my email account.&lt;BR /&gt;&lt;BR /&gt;There is some low volume stuff getting through and I will be reporting what steps are required to STOP that.&lt;BR /&gt;&lt;BR /&gt;Most likely more script modifications.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Thu, 05 Feb 2004 10:11:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/sendmail-config/m-p/3183199#M9610</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2004-02-05T10:11:19Z</dc:date>
    </item>
    <item>
      <title>Re: Sendmail config</title>
      <link>https://community.hpe.com/t5/operating-system-linux/sendmail-config/m-p/3183200#M9611</link>
      <description>Thanks Steven; I think I've about got all the loopholes closed now. It seems that when sendmail sends successfully it creates an entry with "status=Sent" in the body. Didn't find any bogus entries with "status=Sent" in them.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 05 Feb 2004 11:31:34 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/sendmail-config/m-p/3183200#M9611</guid>
      <dc:creator>Vernon Brown_1</dc:creator>
      <dc:date>2004-02-05T11:31:34Z</dc:date>
    </item>
    <item>
      <title>Re: Sendmail config</title>
      <link>https://community.hpe.com/t5/operating-system-linux/sendmail-config/m-p/3183201#M9612</link>
      <description>Vernon,&lt;BR /&gt;&lt;BR /&gt;Those "scans" might be a side-effect of the Novarg/Mydoom virus.  Since it spoofs the sender's address, you may be getting bounces because of it.  Also, I've seen that virus make up its own e-mail addresses and maybe that's part of what you're seeing.&lt;BR /&gt;&lt;BR /&gt;I've been getting virus-laden e-mails with non-existent addresse because of that.&lt;BR /&gt;&lt;BR /&gt;Just something else to keep in mind.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Seth</description>
      <pubDate>Thu, 05 Feb 2004 11:41:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/sendmail-config/m-p/3183201#M9612</guid>
      <dc:creator>Seth Parker</dc:creator>
      <dc:date>2004-02-05T11:41:36Z</dc:date>
    </item>
    <item>
      <title>Re: Sendmail config</title>
      <link>https://community.hpe.com/t5/operating-system-linux/sendmail-config/m-p/3183202#M9613</link>
      <description>Probably my final notes on this topic:&lt;BR /&gt;&lt;BR /&gt;1) if you connect to your mail server telnet mailservername 25 you get a direct connection to the server. If you know a valid email address you are able to type or paste in smtp commands to your hearts content.&lt;BR /&gt;&lt;BR /&gt;2) If you have /etc/mail/genericstable /etc/mail/virtusertable entries like @somedomain.com that will let the abuser of item 1 send email adderss using any from address on the domain whether or not it has a valid user id. The abuser can then cc anybody he wants. Guess who gets blamed for the spam. You must have valid system users before the @ sign in those configuration files.&lt;BR /&gt;&lt;BR /&gt;I think I have slammed the door shut tight on the spammers. I will let you know either here or in my own threads.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Fri, 06 Feb 2004 11:30:53 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/sendmail-config/m-p/3183202#M9613</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2004-02-06T11:30:53Z</dc:date>
    </item>
    <item>
      <title>Re: Sendmail config</title>
      <link>https://community.hpe.com/t5/operating-system-linux/sendmail-config/m-p/3183203#M9614</link>
      <description>I am currently testing a system for dealing with large isps.&lt;BR /&gt;&lt;BR /&gt;aol has a list of valid mail server at &lt;A href="http://postmaster.aol.com" target="_blank"&gt;http://postmaster.aol.com&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;I copied those into my /etc/mail/access file&lt;BR /&gt;&lt;BR /&gt;mail.aol.com    OK&lt;BR /&gt;aol.com         550 Only valid aol mail servers&lt;BR /&gt;@aol.com        550 Only valid aol mail servers&lt;BR /&gt;&lt;BR /&gt;This setup should block all of aol on port 25 except for posted valid outbound and inbound mail servers.&lt;BR /&gt;&lt;BR /&gt;I will post test results.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Fri, 06 Feb 2004 12:36:06 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/sendmail-config/m-p/3183203#M9614</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2004-02-06T12:36:06Z</dc:date>
    </item>
    <item>
      <title>Re: Sendmail config</title>
      <link>https://community.hpe.com/t5/operating-system-linux/sendmail-config/m-p/3183204#M9615</link>
      <description>Don't try my last idea.&lt;BR /&gt;&lt;BR /&gt;It doesn't work.&lt;BR /&gt;&lt;BR /&gt;It blocks aol mail servers completely.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Fri, 06 Feb 2004 12:53:31 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/sendmail-config/m-p/3183204#M9615</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2004-02-06T12:53:31Z</dc:date>
    </item>
  </channel>
</rss>

