Serious bug |
Post Reply |
Author | |
tk
Guest Group |
Post Options
Thanks(0)
Posted: 28 June 2003 at 12:15am |
Spamfilter accepts mail for a bogus user before verifying if that user is valid on the SMTP server. By the time it figures out that the email address is bogus it has already send an OK to the sending SMTP server and closed the connection. It then tries to return the e-mail on a new thread to the bogus return address provided by the spammer causing a bounce message to comeback.
IP addresses, domain name and email addressess have been changed to protect the innocent.
06/27/03 22:58:49:560 -- (352) Connection from: 24.100.112.12 - Originating country : Canada
06/27/03 22:58:50:090 -- (352) Resolving 24.100.112.12 - CPE0040ca347bb4-CM400048344950.cpe.net.cable.rogers.com
06/27/03 22:58:50:090 -- (352) Mail from: bymsejw@yahoo.com
06/27/03 22:58:51:102 -- (352) - MAPS search done... .
06/27/03 22:58:51:102 -- (352) RCPT TO: dummyi@tdummy.com accepted
06/27/03 22:58:51:833 -- (352) EMail from bymsejw@yahoo.com to dummy@dummy.com was queued. Size: 1 KB
06/27/03 22:58:51:883 -- (338) Sending email from bymsejw@yahoo.com to dummy@dummy.com
<=== New Thread =====>
06/27/03 22:58:51:943 -- (352) Disconnect
06/27/03 22:58:52:224 -- (338) EMail from: bymsejw@yahoo.com to: dummy@dummy.com was returned to sender - server error - Invalid recipient
|
|
LogSat
Admin Group Joined: 25 January 2005 Location: United States Status: Offline Points: 4104 |
Post Options
Thanks(0)
|
tk, SpamFilter is designed to send an email back to the sender if the recipient of their email is invalid, has a full mailbox, or similar. In order to avoid the bounce to bounce, did you set an Error Handler Email with a null return address like: "System Administrator" <> in the Customized Items tab? Roberto F. |
|
tk
Guest Group |
Post Options
Thanks(0)
|
No. I just set it to <>. I still don't understand how that's going to help the situation? The sender still thinks that e-mail was delivered to a bogus address. Why doesn't SpamFiler do a verify (VRFY) against the SMTP server before accepting the e-mail? This is a big problem for us because we get hundreds of e-mails for former employees and other e-mail addresses no longer in use and now in the possession of spammers. We could create a list of blocked to e-mail addresses but that would be a long list (or alternatively a white list of good to addressess). |
|
LogSat
Admin Group Joined: 25 January 2005 Location: United States Status: Offline Points: 4104 |
Post Options
Thanks(0)
|
Not all smtp server will allow to verify users with the VRFY command. If you set the return to null <>, when SpamFilter sends the bounce, it will be done so with a null return email, which should end things there. If the sender has an invalid email, nothing should come back to SpamFilter since there was a null return. Things are designed to work this way... Roberto F. |
|
Post Reply | |
Tweet
|
Forum Jump | Forum Permissions You cannot post new topics in this forum You cannot reply to topics in this forum You cannot delete your posts in this forum You cannot edit your posts in this forum You cannot create polls in this forum You cannot vote in polls in this forum |
This page was generated in 0.238 seconds.