Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Incidents
[Top] [All Lists]

Re: ***SPAM*** Re: Massive SPAM Increase {-2.6} {-2.6}

Subject: Re: ***SPAM*** Re: Massive SPAM Increase {-2.6} {-2.6}
Date: Mon, 16 Oct 2006 12:38:08 -0500
--On Monday, October 16, 2006 10:04:30 -0700 benfell@raven.cybernude.org wrote:

Wrong. Completely wrong. Any UNIX-like box with qmail can be configured to send mail out. My laptop, for example. But my domains only receive mail at the servers designated as MX hosts in DNS.

Your idea that an outbound mail host should be listed in DNS indicates a
complete misunderstanding of the purpose of an MX record.  These records
indicate to other MTAs where they should deliver mail *to*, not where they
should accept mail from.

{{{sigh}}} It sure would be nice if you guys would READ before jumping all over this. Of course the MX record indicates where you send mail *to*. But historically thoses hosts were also the ones that accepted mail. And in fact, *many* domains still handle it that way. Yes, some do not, including ours, but that's beside the point.


Furthermore, policyd-*****WEIGHT***** (get it?????) assigns *weights* to various "flaws" (much like spamassassin does to content) and it takes a lot more than one flaw to reject the mail.

If you think that's wrong now, take it up with the author of policyd-weight, not me. And as I have stated **repeatedly**, if you don't believe me, send a test message to geek@stovebolt.com and see if it gets through. To my knowledge, not one person who has done that has had their mail rejected.

Paul Schmehl (pauls@utdallas.edu)
Adjunct Information Security Officer
The University of Texas at Dallas
http://www.utdallas.edu/ir/security/

Attachment: p7soaxSBLSGtG.p7s
Description: S/MIME cryptographic signature

<Prev in Thread] Current Thread [Next in Thread>