Hi, Just think about this: some real and legitimate user may have his/her computer invaded, and used for sending non-authorized e-mails via his/her authorized account. How can this be countered?
Because the computer IS in a non-restricted ip range, the user IS authorized and everything else is fine but the e-mail itself... A nightmare? Is there something like antispam for *outgoing* e-mail? Other approaches: - is it possible to ban any client but webmail? Uninstall outlook, thunderbird and the like, instead use webmail - is it possible to connect to smtp server using VPN instead of directly connecting? I can think of no suggestion when it comes to a invaded computer, but I believe the two suggestions above can be really difficult for a spammer to work with your server, especially the webmail (the spammer will not be able to use his/her programs to send e-mail if you use a webmail, he/she will need to do it by hand, or adapt some auto-response keying system to do it). If you use vpn and webmail, it wil be more difficult still, because that way no out-there computer will be able to reach your webmail system, only the ones your users are using. Also, consider that those suggestions represent changes on user culture, and that is veeeery difficult to accomplish. Best regards, --- Fernando Maciel Souto Maior On Tue, Sep 2, 2014 at 10:37 AM, Lubomir Majersky <[email protected]> wrote: > Hi, > > I use the FW restrictions, but I can not block the relevant > clients from foreign. Therefore, I need to block already authenticated > clients, based on written: > > > "Sometimes it happens that my legitimate user has an infected computer and > occurs leak credentials, for example to Asia and then the attacker from > Asia through my server sends e-mails, because he is successfully > authenticated." > > I have to receive e-mails also from Asia... > > Lubo M. > -- > ~~~~~~~~~~~~~~~~~~~~ > http://LuMaX.acom.sk > ~~~~~~~~~~~~~~~~~~~~ > > Dňa 2. 9. 2014 14:50 Fernando Maior wrote / napísal(a): > > Hello, >> >> What about using iptables or other firewall ruling to rule out >> connections for SMTP from those CIDR ranges? >> >> Atenciosamente, >> --- >> Fernando Maciel Souto Maior >> >>
