David B Funk wrote:

OK, I'm sorry I wasn't clear enough about the environment. The AOL client
was using a web browser (HTTP not SMTP) to sent the message, via a
webmail (HTTP-2-IMAP/SMTP) gateway (running 'IMP'). I understand about
requiring dial-up clients using their ISP for SMTP transactions, but this
was HTTP.

AOL-client (HTTP) => webmail gateway.
webmail gateway (SMTP) => campus SMTP server...

Thus that first hop should NOT have been tagged as violating the DIALUP

Browser <-> webmail is always http. I saw that it was an IMP server - there's an IMP server on this machine too :-) It's the server that is doing both smtp and imap on behalf of the client and the client is telling it what to do via http.


It wasn't the protocol SA was complaining about, it was the fact that the transaction was being carried out by a blocked IP number. Spammers often use http to "bounce" their spam off open http proxies, using port 80/443 to get the server to translate to port 25 on the victim's smtp server. There are RBL tests available for open http proxy servers, too.

I would like to be able to use the DIALUP RBLs for catching SMTP
violators, but that IMP webmail gateway is a very popular thing
on our campus and heavily used.

Of course it is. IMP is a first-class product. As far as this test is concerned, or dial-up IP blocking at all, simply cut out the dialup tests by setting the score to 0 in local.cf. There are enough other RBL tests available.


Best,

Tony

--
Tony Earnshaw

I love the music of Wagner. The only sound that
pleases me more is that of a cat outside my 9th
floor window, trying to cling to the glass with
its claws.

http://j-walk.com/blog/docs/conference.htm
http://www.billy.demon.nl
Mail: [EMAIL PROTECTED]



-------------------------------------------------------
This SF.net email is sponsored by: VM Ware
With VMware you can run multiple operating systems on a single machine.
WITHOUT REBOOTING! Mix Linux / Windows / Novell virtual machines at the
same time. Free trial click here: http://www.vmware.com/wl/offer/345/0
_______________________________________________
Spamassassin-talk mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/spamassassin-talk

Reply via email to