Re: Bypassing BOTNET rules

2007-04-11 Thread Robert Fitzpatrick
On Tue, 2007-04-10 at 07:18 -0700, John Rudd wrote:
 
 Depending on which bypass/exemption you're going to use, either 
 4servers\.com or the IP address are what you want to use.
 
 The bluehill.com part is the smtp HELO argument, and botnet currently 
 ignores that.
 
 

Thanks! Is there any way to pass a destination domain, omitting them
from Botnet?

-- 
Robert



Bypassing BOTNET rules

2007-04-10 Thread Robert Fitzpatrick
I applied BOTNET rules yesterday and have some legitimate mail getting
blocked and looking for the best way to bypass. I added 'bluehill\.com'
to the list of botnet_pass_domains, is that correct or should I be
adding '4servers\.com' or both?

Received: from esmtp.webtent.net ([127.0.0.1])
by localhost (esmtp.webtent.net [127.0.0.1]) (amavisd-new, port 10024)
with ESMTP id hnLlQBEIQsOo for [EMAIL PROTECTED];
Tue, 10 Apr 2007 08:20:27 -0400 (EDT)
Received: from bluehill.com (67-30-129-1.4servers.com [67.30.129.1])
by esmtp.webtent.net (WebTent ESMTP Postfix Internet Mail Gateway) with 
ESMTP i$
for [EMAIL PROTECTED]; Tue, 10 Apr 2007 08:20:27 -0400 (EDT)
Received: from bluehill.com (localhost [127.0.0.1])
by bluehill.com (8.13.1/8.12.10) with ESMTP id l3ACKQxT013801;
Tue, 10 Apr 2007 05:20:26 -0700
Received: (from [EMAIL PROTECTED])
by bluehill.com (8.13.1/8.13.5/Submit) id l3ACKNka013799;
Tue, 10 Apr 2007 05:20:23 -0700


-- 
Robert



Re: Bypassing BOTNET rules

2007-04-10 Thread John Rudd



Depending on which bypass/exemption you're going to use, either 
4servers\.com or the IP address are what you want to use.


The bluehill.com part is the smtp HELO argument, and botnet currently 
ignores that.



Robert Fitzpatrick wrote:

I applied BOTNET rules yesterday and have some legitimate mail getting
blocked and looking for the best way to bypass. I added 'bluehill\.com'
to the list of botnet_pass_domains, is that correct or should I be
adding '4servers\.com' or both?





Received: from bluehill.com (67-30-129-1.4servers.com [67.30.129.1])
by esmtp.webtent.net (WebTent ESMTP Postfix Internet Mail Gateway) with 
ESMTP i$
for [EMAIL PROTECTED]; Tue, 10 Apr 2007 08:20:27 -0400 (EDT)