sb ch wrote to [EMAIL PROTECTED]:
Hello all.
I have used spamassassin well. But I have some problem, about spam mail.
Some spammer have been sending lots of spam mails through /usr/sbin/sendmail via web interface(form mail cgi) from my server.
Surely, I can't delete form mail cgi for some reason.
Yes, but you can use the most recent version, and configure formmail properly. Formmail is not vulnerable to such attacks if kept up to date, and used as documented. The attack you describe is very old, extremely well-known, and very easy to fix without loss of functionality.
I know that Spamassassin acts against incoming spam mails, But is it possible that acts against outgoing spam mails with spamassassin or other system?
SpamAssassin itself won't delete mail. Assuming your local sendmail is on the same server as SpamAssassin, you could use MIMEDefang or procmail to quarantine outgoing mail over a certain score. It's a bit beyond the scope of this mailing list, but certainly within the realm of possibility. I'd lock down formmail first, though.
- Ryan
-- Ryan Thompson <[EMAIL PROTECTED]>
SaskNow Technologies - http://www.sasknow.com 901-1st Avenue North - Saskatoon, SK - S7K 1Y4
Tel: 306-664-3600 Fax: 306-244-7037 Saskatoon Toll-Free: 877-727-5669 (877-SASKNOW) North America
