Andreas Aardal Hanssen wrote:

On Wed, 7 Jul 2004, Tim Showalter wrote:

moving a user without his client being aware of it.  I like this method;
it's cute, and solves a lot of the problems without a hell of a lot of
work.  (I've never tried it personally, though.)


It looks like a good solution, but it has a flaw; mining for the existance
of email addresses is done with a simple DNS lookup. Almost like the VRFY
SMTP command, not necessarily a good idea these days. Such mining can go
undetected for a long period of time, and the washed email lists increase
in value among spammers. It could be solved by using a differently named
DNS entry though, so something like marc.crispin.deskmail.washington.edu,
with some added logic for the end users.

We're looking to split our domain up so we have the externally visable DNS names and the internall visable ones seperated. Currently it's possible to mine for all DNS names in our domain and we want to change that.

Guy
-- --------------------------------------------------------------------
Guy Dawson                    I.T. Manager              Crossflight Ltd
[EMAIL PROTECTED]         07973  797819                01753 776104



**********************************************************************
This email contains the views and opinions of a Crossflight Limited
employee and at this stage are in no way a direct representation of
Crossflight Limited.
This email and any files transmitted with it are confidential and
intended solely for the use of the individual or entity to whom they
are addressed. If you have received this email in error please notify
the system manager. To ensure the integrity and appropriate use of
its email system, Crossflight Limited reserves the right to examine
any email held on its email system or sent to or from it.
This footnote also confirms that this email message has been swept by
MIMEsweeper for the presence of computer viruses.
We strongly recommend that you check this email with your own virus
software as Crossflight Limited will not be held responsible for any
damage caused by viruses as a result of opening this email.
**********************************************************************



Reply via email to