MESSAGE
DATE | 2008-12-18 |
FROM | Ruben Safir
|
SUBJECT | Re: [NYLXS - HANGOUT] tracking mail
|
On Wed, Dec 17, 2008 at 11:30:30AM -0500, Ron Guerin wrote: > Ruben Safir wrote: > > > How is settin up SA going to hel. You'd have to end the recieving side > > of the server and I'd had thought that SA works on the back end when the > > message is being delivered. > > That is correct: > 1) Spammer puts "From: ruben-at-mrbrklyn.com" on some spam > 2) Spammer matches this spam and puts "To: hangout-at-mrbrklyn.com" > 3) Spam is sent reaches NYLXS server > 4) NYLXS server sees mail is from Ruben to Hangout, and accepts mail > 5) Mail passes through SpamAssassin > 6) Instead of being passed along to Majordomo, Procmail kills message > because despite having from "ruben" and to "hangout", message scores > like the dirty spam it is. > > > I just ask everyone to have some patients. I'll know this down like I > > always do as soon as I get home. I get mail spoofing my adress all the > > time. These guys found a crack. > > I'll repeat, there is nothing wrong with your setup. >
There is a couple of problems with this. First, there is no real account for hangout, so there is no ./procmailrc file to hang SA off of. Secondly, the last time I ran spamassasin it pinned the server's CPU resources.
The procmail file for my personal account doesn't apear to be hit. It seems the solution is to prevent domains from not matching the wrong IP addressses. More directly, nothing from mrbrklyn.com should be allowed to come from anywhere accept my local IP addresses, which I actually thought was the case.
Ruben
> > Ther should be a way to prevent sendmail from accepting false accounts > > from wrong IP addresses. > > It's called SPF, but it's got problems. > > > My machines allow email relay from the local network. Maybe that is > > being somehow exploited if Ron is right. > > You're looking for a problem that doesn't exist. Nothing here has been > exploited. Nothing here is relaying mail. Everything is working the > way it's supposed to work. The only thing you want to change is to put > SpamAssassin between Sendmail and Majordomo because neither of them is > in the business of detecting spam. > > I don't know what the case might be for Majordomo, but with Mailman > there's a plugin that allows you to do more sophisticated analysis like > "If this messasge is a list subscriber, deduct one point from the > score". It's not necessary to use it, as the traditional means of > calling SA work just fine (Procmail, Maildrop, etc.) but you may find > something similar for Majordomo if you look. > > - Ron
|
|