Re: [exim] Spamtrap harvesting idea using fake authenticatio…

トップ ページ
このメッセージを削除
このメッセージに返信
著者: Ian Eiloart
日付:  
To: Marc Perkel
CC: exim-users@exim.org users
題目: Re: [exim] Spamtrap harvesting idea using fake authentication

On 6 Jun 2013, at 19:52, Marc Perkel <marc@???> wrote:

> Suppose we reconfigured servers with no authentication configuration to advertise that they take authentication and that you have a fake authenticator that accepts any password.


It might be better to accept only, say, 1% of authentication attempts. That would prevent the hacker from trivially detecting your trap (by authenticating to the same account with two different passwords). You could use the rate limit facility to increase the likelihood of success. Exim doesn't have, as far as I know, a random number generator, but you could perhaps use a hash of the username/password/date string.

--
Ian Eiloart
Postmaster, University of Sussex
+44 (0) 1273 87-3148