>I don't buy this. If you could compromise a relay using IP spoofing, a >much more transparent method than username spoofing (since the latter, >alone, leaves you vulnerable to RBL checks of your IP), why wouldn't >you use that first?
how do you know they don't, but fail due to anti-spoofing at the border router and so fall back to non-spoofed relay attempt? tcp/ip spoofing is probably very rare anyway. There are 100's of 1000's of open relays and proxies, and friendly network operattors, available without spoofing. Len ____________________________________________________________________ www.menandmice.com/DNS-training : DNS Training BIND8NT.MEIway.com: Secure config ; DNS and mail interactions IMGate.MEIway.com : Free, proven config for anti-mail-abuse gateways To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
