PDA

View Full Version : openrelay caveat


xonath
07-29-2004, 06:27 AM
great install to get qmail itself running - not done addons yet ... but tested my server for open relay caveats via "telnet relay-test.mail-abuse.org" and got 1 failure.

checking further proved that I could telnet localhost 25 and do

mail from: <me@mydomain.com>
rcpt to: <me%mydomain.com@mail.myservername.com>

and it would bounce the message back to my email on another server ...

this could obviously be exploited by a spammer ..

I have added the 127. and another ip into the tcp.smtp and reloaded it but it didnt work ...

what dumb dumb thing am I missing and how can this be locked down ???? or it is further on in the reading .. :oops:

thanks ... :?

xonath
07-30-2004, 03:07 PM
great install to get qmail itself running - not done addons yet ... but tested my server for open relay caveats via "telnet relay-test.mail-abuse.org" and got 1 failure.

checking further proved that I could telnet localhost 25 and do

mail from: <me@hotmail.com>
rcpt to: <me%mydomain.com@mail.myservername.com>

and it would bounce the message back to my email box on another server ... eg hotmail

this could obviously be exploited by a spammer ..

I have added the 127. and another ip into the tcp.smtp and reloaded it but it didnt work ...

what dumb dumb thing am I missing and how can this be locked down ???? or it is further on in the reading .. :oops:

I have read the questions and answers and it categorically states that it is not a open relay .... but I have checked all that I can and this does seem to be an issue ... does anyone have a server installed with this method that I can test this on ?????

thanks ... :?