On 2010-06-24 6:08 AM, Matti Haack wrote:
> would  it be possible to check incomming SMTP Passwords against a list
> of regexes and send a warning to the logfile if matching?
> 
> Additionatly  it would be good to check the PW not to be the user part
> or a substring of the userpart of the email adress and the domain name.
> 
> As  many mailserver software does not check or prevent weak passwords,
> this would be helpful to prevent spamming.
> 
> If  this could be implemented, I will write a set aof regexes for weak
> passwords.

Good idea, but why not just use cracklib or something that is already
designed and well tested for something like this:

http://search.cpan.org/dist/Crypt-Cracklib/Cracklib.pm

-- 

Best regards,

Charles

------------------------------------------------------------------------------
ThinkGeek and WIRED's GeekDad team up for the Ultimate 
GeekDad Father's Day Giveaway. ONE MASSIVE PRIZE to the 
lucky parental unit.  See the prize list and enter to win: 
http://p.sf.net/sfu/thinkgeek-promo
_______________________________________________
Assp-test mailing list
Assp-test@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/assp-test

Reply via email to