Yes, that, and to filter traffic destined *to* port 25
from the dialup user to anywhere but the ISP's mail servers.

On the RAS (dialup) router, you might put on an access list 
like this, assuming the ISP mail server is 192.168.1.5 ...

!
access-list 190 allow tcp any host 192.168.1.5 eq smtp
!

This is pretty crude, but more elegant things are
possible, as you can see with Fredy's previous note.

The spammers typically trick a normal end user to
run an PC application that sends mail by connecting 
directly to the remote mail server, be it AOL, Hotmail, 
whatever.  Often the end user has no idea that they
are spamming, they just believe they will get paid to
run a program, and keep it running as long as possible
while they are connected to the internet.

Mickey


At 15:45 04-08-03, Steven Glogger wrote:
-----Start of Original Message----- 
>i think the idea was, to block port 25 of the user.
>so the user (which could use a unsecured mailserver) cannot used as an
>open-relay/proxy.
>
>-steven
>
>> -----Original Message-----
>> From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]
>> Behalf Of Daniel Lorch
>> Sent: Monday, August 04, 2003 3:42 PM
>> To: [EMAIL PROTECTED]
>> Subject: Re: [swinog] Freesurf Range poluted by open relays?!?
>>
>>
>> hi,
>>
>> > Filtering outgoing port 25 makes it so that these "visitors" to the
>> > net can't just connect and spew out thousands of spam messages,
>> > like they often do with these free services.  They can send e-mail
>> > via the provider's mail servers, where presumably there will
>> > be some kind of restriction on the amount of e-mail that can
>> > be sent per unit of time.
>>
>> I don't know whether Freesurf implements rate-limiting (which is
>> an entirely
>> different issue), but the only way of using Freesurf's SMTP is to
>> use Freesurf
>> as your ISP (as far as I'm aware).
>>
>> > I hope that helps...
>>
>> I'm afraid I still don't understand. What does "Blocking port 25"
>> refer to?
>>   a) Disable the service entirely
>>   b) Implement some sort of rate-limiting
>>   c) Use a port different to 25
>>
>> Sorry to nit-pick, but I'm sort of fed up with people claiming
>> that "blocking
>> port 25" will solve all your problems. No more abuse! -
>> Obviously, because no
>> one can send mails anymore. No more Spam! - Obviously, because
>> you can't rece-
>> ive any mails anymore (not even legit mails). Woohoo (?).
>>
>> -daniel
>>
>> ----------------------------------------------
>> [EMAIL PROTECTED] Maillist-Archive:
>> http://www.mail-archive.com/swinog%40swinog.ch/
>>
>
>----------------------------------------------
>[EMAIL PROTECTED] Maillist-Archive:
>http://www.mail-archive.com/swinog%40swinog.ch/
-----End of Original Message----- 

-- 

Mickey Coggins    Tel: +41-79-210-3762  Fax: +41-86-079-210-3762 

----------------------------------------------
[EMAIL PROTECTED] Maillist-Archive:
http://www.mail-archive.com/swinog%40swinog.ch/

Reply via email to