Thanks Noel,

Sure, fair enough. One of the reasons I am looking at running my own email
server is that I don't trust my ISP (servlets.net - spam up the butt coming
from there...) or out of the box solutions that I use for hosting client
sites. (didn't Todd Rundgren have a song 'I hate my ISP')

Then, reading page 351 of the 3rd edition of _Practical Unix and Internet
Security_ (ISBN#0-596-00323-4), it says, "In general, it is not a good
practice for your server to reveal its identity in this fashion."

Servlets.net ISP I don't have control over. James on my machine, I do. 

I would prefer not to display it. The book goes on to say that Sendmail has
an option to disable this (DontBlameSendmail -
http://www.sendmail.org/tips/DontBlameSendmail.html)

Just trying to do some homework - nothing against James!

-Rob

> -----Original Message-----
> From: Noel J. Bergman [mailto:[EMAIL PROTECTED]
> Sent: Saturday, July 05, 2003 7:19 PM
> To: James Users List
> 
> Kervin and Robert,
> 
> Here are the response strings from blueprintinc.com and koberg.com:
> 
>   220 blueprint-tech.com ESMTP Sendmail 8.12.9/8.12.8; Sat, 5 Jul 2003
> 20:45:14 -0400
>   220 s5.servlets.net ESMTP Sendmail 8.9.3/8.9.3; Sat, 5 Jul 2003
> 17:49:29 -0700
> 
> Plus, every e-mail you send conveys information about your workstation,
> operating system, the build of the MUA, etc.
> 
> I also know the open ports on the servers handling your domains, and more
> than you would like for me to know about the services running on each.
> You
> should be more worried about exploits against them.  Running nmap is
> child's
> play.
> 
>       --- Noel



---------------------------------------------------------------------
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]

Reply via email to