image
image

Go Back   macosx.com > Mac Help Forums > Unix & X11

Reply
 
Thread Tools
  #1  
Old August 3rd, 2004, 09:05 PM
Registered User
 
Join Date: Nov 2000
Location: San Francisco
Posts: 53
Thanks: 0
Thanked 0 Times in 0 Posts
trex is on a distinguished road
Postfix and Spam Relays

Hi all,

I'm running Postfix on Panther. I'm getting hit by spam relay attempts on a regular basis. They're not able to relay but still they're hitting the server very frequently. In addition they make up invalid cryptic looking usernames like

dtxsfgroxqlxq@mydomain.com in order to spoof the server.

What can I do to keep them from loading down my server?

I have set local_recipient in postfix to:

local_recipient_maps = unixasswd.byname $alias_maps

I have also set the following for unknown_local_users

unknown_local_recipient_reject_code = 550

this rejects mail - 550 instead of the default of try again - 450.

In addition the following have been set:

mynetworks_style = host
mynetworks = 192.168.1.0/28, 127.0.0.0/8


Please let me know if you have any other suggestions for securing a Postfix server. I'm going to look into chroot setups too...
__________________
Mac Pro Jan 2008 2.8 Ghz OctoCore
Reply With Quote
  #2  
Old August 3rd, 2004, 10:51 PM
scruffy's Avatar
Notorious Olive Counter
 
Join Date: Dec 2000
Location: Soviet Canuckistan
Posts: 1,726
Thanks: 0
Thanked 0 Times in 0 Posts
scruffy is on a distinguished road
I assume you are accepting incoming mail on the Mac, right? If you are only relaying outbound mail from computers on your local network, and not receiving any incoming mail, you could simply block attempts to connect to port 25 at the firewall, for anyone not in the 192.168.1.0/28 net. If it's only for outgoing mail from the local host, then you could just set inet_interfaces=127.0.0.1 and not even listen on external interfaces...

Incidentally, if you specify mynetworks, then postfix ignores mynetworks_style.

Is it really so many connections that it's having a performance impact, or is it more just clogging up the log files?

Anyway, supposedly postfix is pretty easy to run chrooted too.
__________________

What is the robbing of a bank compared to the founding of a bank?
-- Bertold Brecht
Reply With Quote
  #3  
Old August 6th, 2004, 05:15 PM
Registered User
 
Join Date: Nov 2000
Location: San Francisco
Posts: 53
Thanks: 0
Thanked 0 Times in 0 Posts
trex is on a distinguished road
Chrooting Postfix in Panther

--------------
If you are only relaying outbound mail from computers on your local network, and not receiving any incoming mail, you could simply block attempts to connect to port 25 at the firewall, for anyone not in the 192.168.1.0/28 net. If it's only for outgoing mail from the local host, then you could just set inet_interfaces=127.0.0.1 and not even listen on external interfaces...
--------------

People on the internet need to connect to the mail server to send and receive email. So I would need for postfix to listen to connections coming from the internet. I'll look into chrooting postfix. does anyone know of a good tutorial for doing this on a Panter setup?
__________________
Mac Pro Jan 2008 2.8 Ghz OctoCore
Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off
Forum Jump


All times are GMT -5. The time now is 11:02 PM.


Mac Support® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.1.0
Copyright 2000-2008 DigitalCrowd, Inc.