Re: [Exim] Re: Exiscan 4.10-15

Pàgina inicial
Delete this message
Reply to this message
Autor: Larry Rosenman
Data:  
A: Tom Kistner
CC: exim-users
Assumpte: Re: [Exim] Re: Exiscan 4.10-15
On Tue, 2002-09-10 at 09:21, Tom Kistner wrote:
> Jeffrey Wheat wrote:
>
>  >     After seeing this behavoir, I am not comfortable anymore. I can see a
>  > situation where someone forges a mail header with an exiscan tag and sends
>  > a virus. Our mail server sees the tag and allows it to go through without
>  > checking? Is this how it works? It seems to be that way as my staging server
>  > never checks mail.

>
> Make sure that exiscan_crypt_salt is different on all your machines.
>
> To forge a header, someone must know your exiscan_crypt_salt value, so keep it
> secret :)

Tom,
In the mime/tnef/Makefile, you hard code gcc. Can this be changed to
allow the CC variable to be passed in?

I use the OpenUNIX Native compiler (cc).

Thanks,
LER
>
> /tom
>
>
> --
> Tom Kistner <tom@???>
> ICQ 1501527 dcanthrax@efnet
> http://duncanthrax.net
>
>
>
> --
>
> ## List details at http://www.exim.org/mailman/listinfo/exim-users Exim details at http://www.exim.org/ ##
>

--
Larry Rosenman                     http://www.lerctr.org/~ler
Phone: +1 972-414-9812                 E-Mail: ler@???
US Mail: 1905 Steamboat Springs Drive, Garland, TX 75044-6749