Pegasus Mail & Mercury

Welcome to the Community for Pegasus Mail and
The Mercury Mail Transport System, the Internet's longest-serving PC e-mail system!
Welcome to Pegasus Mail & Mercury Sign in | Join | Help
in
Home Blogs Forums Downloads Pegasus Mail Overview Mercury Overview

Spam: Multiple recipients with 1 legit address and Mercury forwards the lot

Last post 07-30-2008, 4:31 by NFG. 2 replies.
Sort Posts: Previous Next
  •  07-28-2008, 8:01

    • NFG is not online. Last active: 01-08-2009, 0:33 NFG
    • Top 500 Contributor
    • Joined on 05-15-2007
    • Member
    • Points 105

    Spam: Multiple recipients with 1 legit address and Mercury forwards the lot

    I noticed a rather serious problem today:

     

    My system's set up to block illegitimate mail.  I demand authentication to relay and I greywall, but today a piece of spam came through with one legitimate address for a local user, and about 12 users on other systems in the CC/BCC fields.  Because one user was legit the message was accepted by Mercury, processed, and 12 messages forwarded to other systems.

     

    This strikes me as a rather serious security hole, and I really don't know how to stop it.  Any suggestions?

    Filed under: , ,
  •  07-28-2008, 9:06

    • David Harris is not online. Last active: 01-06-2009, 22:19 David Harris
    • Top 10 Contributor
    • Joined on 01-31-2007
    • New Zealand
    • Contributor
    • Points 7,970
    • SystemAdministrator

    Re: Spam: Multiple recipients with 1 legit address and Mercury forwards the lot

    NFG:

    My system's set up to block illegitimate mail. I demand authentication to relay and I greywall, but today a piece of spam came through with one legitimate address for a local user, and about 12 users on other systems in the CC/BCC fields. Because one user was legit the message was accepted by Mercury, processed, and 12 messages forwarded to other systems.



    I don't want to sound like I'm in denial on this, but I don't think it happened the way you describe it. I can't find any way of getting Mercury to do this in testing here - the non-local addresses always return the "We do not relay with RFC2554 authentication" message when I try it, and I've just tried quite a range of possible combinations.

    The only scenario that works here is if the sender is actually authenticated, in which case you have an issue of trust with a specific user rather than a technical problem. A variation on the same problem might happen if you have a connection control entry that specifically allows the connecting machine to relay, but once again, that is a configuration issue rather than a security hole.

    If you can show me a session log illustrating a clear case of improper relaying, I'll fix it as a matter of urgency, but I'm pretty confident you won't be able to do that.

    Cheers!

    -- David --

  •  07-30-2008, 4:31

    • NFG is not online. Last active: 01-08-2009, 0:33 NFG
    • Top 500 Contributor
    • Joined on 05-15-2007
    • Member
    • Points 105

    Re: Spam: Multiple recipients with 1 legit address and Mercury forwards the lot

    Thanks for your reply, David.

     

    I confess I am not sure it happened the way I describe, but it was the only thing that made sense to me at the time.  I will investigate the whitelisted senders and see if I can figure out where it all went wrong.

View as RSS news feed in XML

Copyright © 2007 David Harris / Peter Strömblad. All Rights Reserved. | Terms of Use | Privacy Statement
Questions/Problems with community.pmail.com? | Visit our Hoster: PraktIT | Pegasus Mail Home Page