<br><font size=2 face="sans-serif">I'm sure you can do that with the MDA
(Procmail) but I'm not sure it will get to the MDA, I think It just stays
in the MTA (sendmail)?</font>
<br><font size=2 face="sans-serif"><br>
</font><img src=cid:_1_063F3870063F3648004B00D685257444>
<br>
<br>
<br>
<table width=100%>
<tr valign=top>
<td width=40%><font size=1 face="sans-serif"><b>Cyber Source <peter@thecybersource.com></b>
</font>
<br><font size=1 face="sans-serif">Sent by: nflug-bounces@nflug.org</font>
<p><font size=1 face="sans-serif">05/09/2008 09:36 AM</font>
<table border>
<tr valign=top>
<td bgcolor=white>
<div align=center><font size=1 face="sans-serif">Please respond to<br>
nflug@nflug.org</font></div></table>
<br>
<td width=59%>
<table width=100%>
<tr valign=top>
<td>
<div align=right><font size=1 face="sans-serif">To</font></div>
<td><font size=1 face="sans-serif">nflug@nflug.org</font>
<tr valign=top>
<td>
<div align=right><font size=1 face="sans-serif">cc</font></div>
<td>
<tr valign=top>
<td>
<div align=right><font size=1 face="sans-serif">Subject</font></div>
<td><font size=1 face="sans-serif">Re: [nflug] Sendmail Percent Hack</font></table>
<br>
<table>
<tr valign=top>
<td>
<td></table>
<br></table>
<br>
<br>
<br><tt><font size=2>I would first think to create a rule to deny any email
address with a %. <br>
I can't recall what file this is to edit.<br>
<br>
justin.bennett@dynabrade.com wrote:<br>
><br>
> Hey Guys,<br>
><br>
> I have a mail server running sendmail-8.12.11
and have found <br>
> it to be susceptible to a percent hack Where if I address an email
to <br>
> anyuser at a domain supported by this server but place the real <br>
> recipient address in the username portion (replaceing the @ with a
%) <br>
> it will relay the message. This can be exploited by spammers.<br>
><br>
> For example if you send a message to:<br>
><br>
> joesmoe%company.com@mydomain.com<br>
><br>
> The message will be delivered to the mailserver for mydomain.com then
<br>
> relayed by sendmail to the appropriate place.<br>
><br>
> Is there a way to turn off this 'feature' in sendmail.<br>
><br>
> Thanks<br>
> Justin<br>
><br>
><br>
> ------------------------------------------------------------------------<br>
><br>
> _______________________________________________<br>
> nflug mailing list<br>
> nflug@nflug.org<br>
> </font></tt><a href=http://www.nflug.org/mailman/listinfo/nflug><tt><font size=2>http://www.nflug.org/mailman/listinfo/nflug<br>
> <br>
_______________________________________________<br>
nflug mailing list<br>
nflug@nflug.org<br>
</font></tt><a href=http://www.nflug.org/mailman/listinfo/nflug><tt><font size=2>http://www.nflug.org/mailman/listinfo/nflug<br>
</font></tt></a></a>
<br>