Re: need help for controlling authenticated realy

2011-04-23 Thread Larry Vaden
On Sat, Apr 23, 2011 at 8:45 PM, Rajesh Kumar Mallah wrote: > > Any help would be greatly appreciated. I second your motion.

Re: need help for controlling authenticated realy

2011-04-23 Thread Evan Platt
Enforce a better password policy - our work password policy is minimum 8 characters, and 3 out of the 4 of the following: Upper Case Lower case Number Special Character - any shift + top row number) - ie !@#$%^&*( By this policy hellowhowareyou wouldn't work because it only has lower case letters.

Re: need help for controlling authenticated realy

2011-04-23 Thread Daniel Bromberg
On 4/23/2011 10:09 PM, Evan Platt wrote: [snip] On Sat, Apr 23, 2011 at 6:45 PM, Rajesh Kumar Mallah wrote: Hi, We allow relaying of email via our server to our clients using authentication. The problem is that some miscreants have got hold of our clients password and are using our email ser

Re: need help for controlling authenticated realy

2011-04-23 Thread Evan Platt
On Sat, Apr 23, 2011 at 7:17 PM, Daniel Bromberg wrote: > Can you stop sending to postfix-us...@cloud9.net? It's messing up my filter > and will probably mess up lots of other automated filters as well. Use > postfix-users@postfix.org. Sorry - I did a reply all to the e-mail. You should be filte

RE: need help for controlling authenticated realy

2011-04-23 Thread mallah.raj...@gmail.com
-users@postfix.org Subject: Re: need help for controlling authenticated realy On Sat, Apr 23, 2011 at 7:17 PM, Daniel Bromberg wrote: > Can you stop sending to postfix-us...@cloud9.net? It's messing up my filter > and will probably mess up lots of other automated filters as well. Us

RE: need help for controlling authenticated realy

2011-04-23 Thread mallah.raj...@gmail.com
Sorry missed to say that it is not shared password system. Sent from my Nokia phone -Original Message- From: Evan Platt Sent: 24/04/2011, 8:04 AM To: Daniel Bromberg Cc: postfix-users@postfix.org Subject: Re: need help for controlling authenticated realy On Sat, Apr 23, 2011 at 7:17 PM

Re: need help for controlling authenticated realy

2011-04-24 Thread Wietse Venema
Rajesh Kumar Mallah: [ Charset ISO-8859-1 unsupported, converting... ] > Hi, > > We allow relaying of email via our server to our clients using authentication. > The problem is that some miscreants have got hold of our clients password > and are using our email server to send SPAM after successful

Re: need help for controlling authenticated realy

2011-04-24 Thread Bastian Blank
On Sun, Apr 24, 2011 at 07:15:34AM +0530, Rajesh Kumar Mallah wrote: > We allow relaying of email via our server to our clients using authentication. > The problem is that some miscreants have got hold of our clients password > and are using our email server to send SPAM after successfully authenti

RE: need help for controlling authenticated realy

2011-04-24 Thread mallah.raj...@gmail.com
Sent from my Nokia phone -Original Message- From: Wietse Venema Sent: 24/04/2011, 6:23 PM To: Subject: Re: need help for controlling authenticated realy Rajesh Kumar Mallah: [ Charset ISO-8859-1 unsupported, converting... ] > Hi, > > We allow relaying of email via our serv

RE: need help for controlling authenticated realy

2011-04-24 Thread Dennis Carr
"mallah.raj...@gmail.com" wrote: > > >Coming back to real issue,i have already initiated password policy >control. But i feel its not impossible for the enduser to somehow leak >the password, passwords are commonly >remembered by muas and possibility of virus and malware sniffing out >the pass

Re: need help for controlling authenticated realy

2011-04-24 Thread Patrick Ben Koetter
* mallah.raj...@gmail.com : > i am using policyd but it looks like it has no control once the initial > connection is established , authenticated and pipelining is being used to > pump spam . Is it really so?. At least version 1 of policyd can throtte SASL authenticated senders. I don't know about

Re: need help for controlling authenticated realy

2011-04-24 Thread Nikolaos Milas
On 24/4/2011 5:09 πμ, Evan Platt wrote: Enforce a better password policy - our work password policy is minimum My 2c: Check your server logs to see if someone found some password(s) by brute-force (you'll see multiple failed logins). * If yes, enforce a strict password policy as sugges

Re: need help for controlling authenticated realy

2011-04-24 Thread Rajesh Kumar Mallah
Dear Patrixk, I express my gratitude to this list . I am grateful for the people in the list who contribute their gems. I am new to postfix (qmail migrant) , but with a lively list like this i am feeling home. the postcat is very handy to print the headers and contents i am sure i should be able

Re: need help for controlling authenticated realy

2011-04-24 Thread Rajesh Kumar Mallah
Dear Patrick, I did a testing and i was able to successful in linking the message to the original username that was used in authenticating the connection for message delivery. the key was to grep '9A2E240330CE2' from the header 33 Received: from laptop.localnet (unknown [122.161.212.115]) 34