Re: smtp probes

From: Wichert Akkerman (wichertat_private)
Date: Mon Aug 20 2001 - 16:55:24 PDT

  • Next message: Jason Spence: "Re: Do you know any Day 0 hacks use port 139? (fwd)"

    Previously Hugo van der Kooij wrote:
    > At least valinux and sourceforge setup a connect and will do some
    > verification before they accept email. It could be that this behaviour is
    > getting copied on other systems as well. I usually get some probes from
    > them after a message from me is accepted via a mailinglist from
    > securityfocus.
    
    They do to make sure the sender address is valid so they can deliver
    a bounce if needed. That check seems to stop a fairly large amount
    of spam very effectively. It's an exim feature.
    
    Wichert.
    
    -- 
      _________________________________________________________________
     /       Nothing is fool-proof to a sufficiently talented fool     \
    | wichertat_private                   http://www.liacs.nl/~wichert/ |
    | 1024D/2FA3BC2D 576E 100B 518D 2F16 36B0  2805 3CB8 9250 2FA3 BC2D |
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Mon Aug 20 2001 - 18:02:32 PDT