Preventing Dark Mail Attacks

Discuss the Scalix Server software

Moderators: ScalixSupport, admin

codehaxor
Posts: 34
Joined: Tue May 30, 2006 9:12 am

Preventing Dark Mail Attacks

Postby codehaxor » Thu Aug 03, 2006 11:42 am

Dark mail attacks is an attack wherein an attacker uses a program to try to guess a valid user in a domain by using a dictionary file, this gets so irritating because each time an invalid user is sent an email the scalix server automatically replies to the senders email address. Is there a way to prevent this aside from block listing the user?

ScalixSupport
Scalix
Scalix
Posts: 5503
Joined: Thu Mar 25, 2004 8:15 pm

Postby ScalixSupport » Fri Aug 04, 2006 8:35 am

In a standard Scalix setup an unknown recipient will automatically get a 550 response. If that is not the case with your setup you need to tell us how you set it up.

Cheers,

Sascha.

graemef
Posts: 81
Joined: Mon May 23, 2005 6:52 am

Postby graemef » Sun Aug 06, 2006 8:30 pm

I actually have the same problem. Currently I have two MX records for our office, the first is a direct to our email server, the second is to a catchall account at an ISP in the event of our internet being down. The second account gets an unreasonable amount of email for whatever reason. When this account is checked I use fetchmail to retrieve the emails then forward them to Scalix. The unfortunate side effect of this is that if the account does not exist sendmail sends a response back. This is generating heaps of outgoing mail.

Anyway I think this is what is happening :-) I would like to disable the bouncing of emails altogether if I can.
TIA


Return to “Scalix Server”



Who is online

Users browsing this forum: No registered users and 4 guests

cron