Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chriss Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Open Relay

Status
Not open for further replies.

jpmigue

MIS
Mar 30, 2001
11
GB

I am running sendmail 8.11.2 on a redhat system. The system runs as an open relay and has been blacklisted. It is documented that the system had a buggy linuxconf that means it is susceptible to the trailing @ hack. I cannot find a compatible more recent linuxconf and have therefore tried the following but the percent hack still gets through:

Recompiled sendmail.cf using m4
Manually edited sendmail.cf and inserted documented check_rcpt rules.
Inserted the documented check_rcpt rules into a newly compiled sendmail.cf
I thought this version of sendmail barred relaying mails by default!

Any assistance greatfully received

James
 
James,
I used to use linuxconf but I read that it had some major problems & it wasn't being supported anymore. Try using webmin instead, which can be used to configure your linux server - including sendmail.
On the relay problem, check out these links. I believe there is something wrong with your /etc/mail/access & /etc/mail/relay-domains:



Hope this helps,
Keith
 
Never use linuxconf to configure sendmail it's broken.
check your sendmail.mc for the following
FEATURE(`RELAY_ENTIRE_DOMAIN')
if it is there remove it as this allows relaying for entire class m
You will also have to configure your box to relay domain literal to be removed from some DSBL lists (RFC 1122 /1123 methinks).

There is no God, only 10001010
 
I know linuxconf is broken, it is the reason that my box relays. The .mc file I am testing has only the followig entries:

OSTYPE(`linux')
DOMAIN(`generic')
FEATURE(`nouucp', `reject')
MAILER(`local')
MAILER(`smtp')


The system as a rule does not relay but always falls foul of the trailing @ in a rcpt address. Every piece of documentation I come across tells me what I know - it is the check_rcpt rule that should be catching this - but I still cannot fix the trailing @ hack.

Cheers

James
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top