On 21/12/09 22:11 +07:00 Novel wrote :
>> >Doh lupa kasih Warning : Don't do this if your MDaemon not version 10.x
>> >or above.
> huahuahua =(( diskriminasiii hiks

Saya menunggu fitur "Exempt authenticated sessions (lookup will defer
until after MAIL)" sejak MDaemon versi 6.x, berkali-kali menyampaikan
wish list dan baru di versi 10.0.1 lah fitur itu diimplementasi.
Tanpa fitur delay verification akan jadi senjata makan tuan (user
sendiri yg terblock).

Di MD 11.0 nanti fitur ini akan diperbaiki lagi, dipermudah dalam
penerapannya.

Mulai minggu kemarin saya mulai uji coba mengaktifkan
[x] ...send 501 and close connection on forged identification (caution)

karena spammer banyak yg makin pintar memalsu FQDN host identity.
Misalkan ini

Mon 2009-12-21 21:08:37: [3334:1] Session 3334; child 1; thread 0
Mon 2009-12-21 21:08:37: [3334:1] Accepting SMTP connection from
[125.161.199.29:4004] to [203.130.233.2:25]
Mon 2009-12-21 21:08:37: [3334:1] --> 220 dutaint.co.id ESMTP MDaemon
11.0.0h; Mon, 21 Dec 2009 21:08:37 +0700
Mon 2009-12-21 21:08:37: [3334:1] <-- EHLO gmail.com
Mon 2009-12-21 21:08:37: [3334:1] --> 250-dutaint.co.id Hello gmail.com,
pleased to meet you
Mon 2009-12-21 21:08:37: [3334:1] --> 250-ETRN
Mon 2009-12-21 21:08:37: [3334:1] --> 250-AUTH=LOGIN
Mon 2009-12-21 21:08:37: [3334:1] --> 250-AUTH LOGIN CRAM-MD5
Mon 2009-12-21 21:08:37: [3334:1] --> 250-8BITMIME
Mon 2009-12-21 21:08:37: [3334:1] --> 250 SIZE 20480000
Mon 2009-12-21 21:08:37: [3334:1] <-- MAIL FROM:<[email protected]>
Mon 2009-12-21 21:08:37: [3334:1] Performing IP lookup (gmail.com)
Mon 2009-12-21 21:08:37: [3334:1] *  D=gmail.com TTL=(1) A=[209.85.231.83]
Mon 2009-12-21 21:08:37: [3334:1] *  D=gmail.com TTL=(1) A=[209.85.231.18]
Mon 2009-12-21 21:08:37: [3334:1] *  D=gmail.com TTL=(1) A=[209.85.231.19]
Mon 2009-12-21 21:08:37: [3334:1] ---- End IP lookup results
Mon 2009-12-21 21:08:37: [3334:1] --> 501 This server will not accept
forged credentials; you are not 'gmail.com'
Mon 2009-12-21 21:08:37: [3334:1] SMTP session terminated (Bytes in/out:
50/291)

syaf...@home:~$ host 125.161.199.29
29.199.161.125.in-addr.arpa domain name pointer
29.subnet125-161-199.speedy.telkom.net.id.

Nggak nyangka juga saat facebook ternyata ikut kereject krn FQDN
hostnamenya tidak match, sehingga terpaksa di whitelist.

Sat 2009-12-19 12:34:41: ----------
Sat 2009-12-19 12:34:40: [7190:4] Session 7190; child 4; thread 0
Sat 2009-12-19 12:34:40: [7190:4] Accepting SMTP connection from
[69.63.178.178:37017] to [203.130.233.2:25]
Sat 2009-12-19 12:34:40: [7190:4] --> 220 dutaint.co.id ESMTP MDaemon
11.0.0g; Sat, 19 Dec 2009 12:34:40 +0700
Sat 2009-12-19 12:34:44: [7190:4] <-- EHLO mx-out.facebook.com
Sat 2009-12-19 12:34:44: [7190:4] --> 250-dutaint.co.id Hello
mx-out.facebook.com, pleased to meet you
Sat 2009-12-19 12:34:44: [7190:4] --> 250-ETRN
Sat 2009-12-19 12:34:44: [7190:4] --> 250-AUTH=LOGIN
Sat 2009-12-19 12:34:44: [7190:4] --> 250-AUTH LOGIN CRAM-MD5
Sat 2009-12-19 12:34:44: [7190:4] --> 250-8BITMIME
Sat 2009-12-19 12:34:44: [7190:4] --> 250 SIZE 20480000
Sat 2009-12-19 12:34:44: [7190:4] <-- MAIL
FROM:<[email protected]>
Sat 2009-12-19 12:34:44: [7190:4] Performing IP lookup (mx-out.facebook.com)
Sat 2009-12-19 12:34:44: [7190:4] *  D=mx-out.facebook.com TTL=(19)
A=[69.63.179.26]
Sat 2009-12-19 12:34:44: [7190:4] *  D=mx-out.facebook.com TTL=(19)
A=[69.63.176.71]
Sat 2009-12-19 12:34:44: [7190:4] ---- End IP lookup results
Sat 2009-12-19 12:34:44: [7190:4] --> 501 This server will not accept
forged credentials; you are not 'mx-out.facebook.com'
Sat 2009-12-19 12:34:44: [7190:4] SMTP session terminated (Bytes in/out:
78/311)
Sat 2009-12-19 12:34:44: ----------

syaf...@home:~$ host 69.63.178.178
178.178.63.69.in-addr.arpa domain name pointer outmail019.snc1.tfbnw.net.

syaf...@home:~$ host outmail019.snc1.tfbnw.net
outmail019.snc1.tfbnw.net has address 69.63.178.178

-- 
syafril
-------
Syafril Hermansyah

Running MDaemon 11.0.0 Beta G


The chief danger in life is that you may take too many precautions.
        -- Alfred Adler


--[MDaemon-L]------------------------------------------------
Milis ini untuk Diskusi antar pengguna MDaemon Mail Server.

Netiket: <http://www.netmeister.org/news/learn2quote>
Arsip: <http://mdaemon-l.dutaint.com>
Henti Langgan: Kirim mail ke MDaemon-L-unsubscribe [at] dutaint.com
Berlangganan: kirim mail ke MDaemon-L-subscribe [at] dutaint.com
Versi terakhir MD 10.1.2, SP 4.0.2, OC 2.2.3, SG 2.0.2, PP 1.1

Kirim email ke