[Mimedefang] trouble with filter_sender and faked mail from my domain to my domain

Steffen Kaiser skmimedefang at smail.inf.fh-bonn-rhein-sieg.de
Wed Aug 16 02:59:04 EDT 2006


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Tue, 15 Aug 2006, Scott Harris wrote:

> Aug 15 15:06:17 mail2 mimedefang.pl[9795]: Scooter: sender->
> <uucp at mydomain.com>, host->87.49.57.14,
> hostname->0x5731390e.kjnxx10.adsl-dhcp.tele.dk,
> helo->0x5731390e.kjnxx10.adsl-dhcp.tele.dk
>
> Does my filter look correct?  It is based on the one from
> the web site.

Actually, the filter does not correspond to your description.
You reject hosts, that use a HELO argument that ends in your domain, but 
are not one of the listed hosts. So this filter_sender() let pass 
the mail correctly.
No sender check is made.

BTW: The terms From: and To: usually apply to the headers of the mail, in 
filter_sender() you can check the envelope MAIL FROM: only.

Bye,

- -- 
Steffen Kaiser
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (GNU/Linux)

iQEVAwUBROLCOugJIbZtwg6XAQK7Bwf/QcAmxP2rp9QjYa7tiUGC9NpJJSA6deh8
KyGUG2125tcriuOSBONl9L77oMINPAWSHgcM0e6KpjBSIzyfiosU4LIxVgYnMTx2
YhUWzRslMax9FnTrXUkNqQXYA3QFfGz/CIeg/QML4cXAw14fGX2tXRlBCSjEOlw5
X4nEQK/ALguO6aSsbEAi2fTCDNHK3/QT+p2zMChiTuJkeKRJ9BCEsKyA+iBeraAw
kK7dkpX2fDJNYj7ujNKmfQcvyo+RmvMNSvCD2USHa+WPFYYQHO/J4Mj7TTHzKCkL
tLLjZ9HPVpIlZMEXvjwqChsJeRoFGeFrn5v/SwcX+PdCb/m0iVgLiw==
=Ebmx
-----END PGP SIGNATURE-----



More information about the MIMEDefang mailing list