on this note, why does Imail allow an outside entity to connect and send
mail even if only internally, using one of my own email addresses, i too
have the auth turned on, and my users have to enter their passwords before
they can send mail, how does someone else come in and send mail internally
without proper credentials. I understand that it is Imails job to process
incoming mail, but why does it allow a from address of one of my own users,
it does on the other hand always block that external address these ppl
always try to sneak into the mix. I have noticed mainly that most of this
mail comes from addresses in the that are actually a list or alias. not to
mention i really dont understand why even a spam company would go thru so
much effort to get to 'just' my company, knowing full well that external
mail will not get out, and eventually their domain will be blocked entirely
from access.
well theres my rant, i guess, any ideas out there how to stop this type of
activity.

Don


-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Sanford
Whiteman
Sent: Tuesday, June 04, 2002 11:16 AM
To: Ken Innes
Subject: Re[6]: [IMail Forum] no message header


>>From <[EMAIL PROTECTED]> Tue Jun 04 12:14:15 2002
> Received: from sport158.com [From <[EMAIL PROTECTED]> Tue Jun 04 12:14:15
> 2002
> Received: from sport158.com [66.46.195.18] by ekos.com with ESMTP
>   (SMTPD32-7.10) id A754C232065A; Tue, 04 Jun 2002 12:14:12 -0400
> X-UIDL: 322766513] by ekos.com with ESMTP
>   (SMTPD32-7.10) id A754C232065A; Tue, 04 Jun 2002 12:14:12 -0400
> X-UIDL: 322766513

Is this the EXACT text (less the quote > marks)? If so, it looks Imail
is  munging  two  copies  of  the  same message together upon receipt.
Whether  this is the result of a deliberate hack or some badly written
spam-blaster is not clear.

Let  us  know if that's a straight cut-and-paste from MAIN.MBX. If so,
it's not something seen before and is need of prompt research.

> What really SCARES me about this, is that the 'from' IP, 66.46.195.18,
> is MY IP! A lookup of sport158.com reveals that he is at 210.82.124.68.
> My concern is, if this person can fool my server into thinking he is
> 66.46.195.18 (ie., the local host), can he turn me into a SPAM
> relay even tho' I have relay set to 'Relay mail addreses' and
> there are only 3 specific ip's allowed to relay?

I would not yet worry that he has relayed through your server; this is
stil  locally  addressed mail. The problem would appear to be that the
sending  IP is not properly added to the Received: header, making such
messages  completely  untraceable  (if  receiving  MTAs cooperate with
RFCs,  the  last Received: is the only piece of reliable information).
Note  that  looking  up  sport158.com  is  useless--the EHLO is easily
forged.

-Sandy


Please visit http://www.ipswitch.com/support/mailing-lists.html
to be removed from this list.

An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/

Please visit the Knowledge Base for answers to frequently asked
questions:  http://www.ipswitch.com/support/IMail/


Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/

Please visit the Knowledge Base for answers to frequently asked
questions:  http://www.ipswitch.com/support/IMail/

Reply via email to