Sat Oct 9 16:50:37 2004 e.s.t
EVENTS
 FREE
SOFTWARE
INSTITUTE

POLITICS
JOBS
MEMBERS'
CORNER

MAILING
LIST

NYLXS Mailing Lists and Archives
NYLXS Members have a lot to say and share but we don't keep many secrets. Join the Hangout Mailing List and say your peice.
2013-06-18 | 2013-05-18 | 2013-04-18 | 2013-03-18 | 2013-02-18 | 2013-01-18 | 2012-12-18 | 2012-11-18 | 2012-10-18 | 2012-09-18 | 2012-08-18 | 2012-07-18 | 2012-06-18 | 2012-05-18 | 2012-04-18 | 2012-03-18 | 2012-02-18 | 2012-01-18 | 2011-12-18 | 2011-11-18 | 2011-10-18 | 2011-09-18 | 2011-08-18 | 2011-07-18 | 2011-06-18 | 2011-05-18 | 2011-04-18 | 2011-03-18 | 2011-02-18 | 2011-01-18 | 2010-12-18 | 2010-11-18 | 2010-10-18 | 2010-09-18 | 2010-08-18 | 2010-07-18 | 2010-06-18 | 2010-05-18 | 2010-04-18 | 2010-03-18 | 2010-02-18 | 2010-01-18 | 2009-12-18 | 2009-11-18 | 2009-10-18 | 2009-09-18 | 2009-08-18 | 2009-07-18 | 2009-06-18 | 2009-05-18 | 2009-04-18 | 2009-03-18 | 2009-02-18 | 2009-01-18 | 2008-12-18 | 2008-11-18 | 2008-10-18 | 2008-09-18 | 2008-08-18 | 2008-07-18 | 2008-06-18 | 2008-05-18 | 2008-04-18 | 2008-03-18 | 2008-02-18 | 2008-01-18 | 2007-12-18 | 2007-11-18 | 2007-10-18 | 2007-09-18 | 2007-08-18 | 2007-07-18 | 2007-06-18 | 2007-05-18 | 2007-04-18 | 2007-03-18 | 2007-02-18 | 2007-01-18 | 2006-12-18 | 2006-11-18 | 2006-10-18 | 2006-09-18 | 2006-08-18 | 2006-07-18 | 2006-06-18 | 2006-05-18 | 2006-04-18 | 2006-03-18 | 2006-02-18 | 2006-01-18 | 2005-12-18 | 2005-11-18 | 2005-10-18 | 2005-09-18 | 2005-08-18 | 2005-07-18 | 2005-06-18 | 2005-05-18 | 2005-04-18 | 2005-03-18 | 2005-02-18 | 2005-01-18 | 2004-12-18 | 2004-11-18 | 2004-10-18 | 2004-09-18 | 2004-08-18 | 2004-07-18 | 2004-06-18 | 2004-05-18 | 2004-04-18 | 2004-03-18 | 2004-02-18 | 2004-01-18 | 2003-12-18 | 2003-11-18 | 2003-10-18 | 2003-09-18 | 2003-08-18 | 2003-07-18 | 2003-06-18 | 2003-05-18 | 2003-04-18 | 2003-03-18 | 2003-02-18 | 2003-01-18 | 2002-12-18 | 2002-11-18 | 2002-10-18 | 2002-09-18 | 2002-08-18 | 2002-07-18 | 2002-06-18 | 2002-05-18 | 2002-04-18 | 2002-03-18 | 2002-02-18 | 2002-01-18 | 2001-12-18 | 2001-11-18 | 2001-10-18 | 2001-09-18 | 2001-08-18 | 2001-07-18 | 2001-06-18 | 2001-05-18 | 2001-04-18 | 2001-03-18 | 2001-02-18 | 2001-01-18 | 2000-12-18 | 2000-11-18 | 2000-10-18 | 2000-09-18 | 2000-08-18 | 2000-07-18 | 2000-06-18 | 2000-05-18 | 2000-04-18 | 2000-03-18 | 2000-02-18 | 2000-01-18 | 1999-12-18

Key: archive Value: 2008-12-01

Key: id Value: 538652

MESSAGE
DATE 2008-12-19
FROM Ruben Safir
SUBJECT Subject: [NYLXS - HANGOUT] [Fwd: Re: admin question]
From lest-hangout-at-mrbrklyn.com Fri Dec 19 00:26:41 2008
Received: from www2.mrbrklyn.com (localhost [127.0.0.1])
by www2.mrbrklyn.com (8.13.1/8.13.1/SuSE Linux 0.7) with ESMTP id mBJ5Qdd8031681
for ; Fri, 19 Dec 2008 00:26:41 -0500
Received: (from majordomo-at-localhost)
by www2.mrbrklyn.com (8.13.1/8.13.1/Submit) id mBJ5QdaH031680
for hangout-outgoings; Fri, 19 Dec 2008 00:26:39 -0500
X-Authentication-Warning: www2.mrbrklyn.com: majordomo set sender to lest-hangout-at-nylxs.com using -f
Received: from [68.167.17.98] (www2.mrbrklyn.com [68.167.17.98])
by www2.mrbrklyn.com (8.13.1/8.13.1/SuSE Linux 0.7) with ESMTP id mBJ5Qaap031677
for ; Fri, 19 Dec 2008 00:26:38 -0500
Message-ID: <494B308B.403-at-mrbrklyn.com>
Date: Fri, 19 Dec 2008 00:26:35 -0500
From: Ruben Safir
User-Agent: Thunderbird 2.0.0.18 (X11/20081105)
MIME-Version: 1.0
To: hangout-at-mrbrklyn.com
Subject: [NYLXS - HANGOUT] [Fwd: Re: admin question]
Content-Type: multipart/mixed;
boundary="------------080401010407080508080804"
Sender: lest-hangout-at-mrbrklyn.com
Precedence: bulk
Reply-To: hangout-at-mrbrklyn.com

This is a multi-part message in MIME format.
--------------080401010407080508080804
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit



--------------080401010407080508080804
Content-Type: message/rfc822;
name="Re: admin question.eml"
Content-Transfer-Encoding: 7bit
Content-Disposition: inline;
filename="Re: admin question.eml"

X-Account-Key: account2
X-Mozilla-Keys:
Received: from linuxmafia.com (linuxmafia.com [198.144.195.186])
by www2.mrbrklyn.com (8.13.1/8.13.1/SuSE Linux 0.7) with ESMTP id mBIMdr2v027496
for ; Thu, 18 Dec 2008 17:39:55 -0500
Received: from rick by linuxmafia.com with local (Exim 4.61 #1 (EximConfig 2.0))
id 1LDRWx-0000qH-El by authid
for ; Thu, 18 Dec 2008 14:39:43 -0800
Date: Thu, 18 Dec 2008 14:39:42 -0800
From: Rick Moen
To: Ruben Safir
Subject: Re: admin question
Message-ID: <20081218223942.GA8960-at-linuxmafia.com>
References: <20081217213343.GT8960-at-linuxmafia.com> <20081218125805.GA19481-at-www2.mrbrklyn.com> <20081218195002.GY8960-at-linuxmafia.com> <494AC3FD.3030707-at-mrbrklyn.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <494AC3FD.3030707-at-mrbrklyn.com>
X-Mas: Bah humbug.
User-Agent: Mutt/1.5.11+cvs20060403
X-SA-Exim-Connect-IP:
X-SA-Exim-Mail-From: rick-at-linuxmafia.com

Quoting Ruben Safir (ruben-at-mrbrklyn.com):

> Rick Moen wrote:
> > Quoting Ruben Safir (ruben-at-mrbrklyn.com):
> >
> >> Rick
> >>
> >> Do you know of a way of limiting the sendmail to recieving mail
> >> from my local ip addresses to my local network only?
> >>
> >> Or maiybe you know someone who might know? I have some spammer
> >> sending my mailing list mail spoofing my email address. They are
> >> evidently smart enough to confirm my name as existing from the SMTP
> >> connection.
> >
> > Here's something else you're not going to want to hear: The above
> > comments suggest you've almost certainly carried forward a sendmail
> > configuration from many years ago that is now woefully obsolete, and
> > is as a result shooting you in the foot. This happens.
> >
> > The reason I say that is you've described a problem that hasn't been
> > present for many year in default configurations of any common *ix
> > MTA. Logically, that means it's an artifact of your local config.
> >
> > Generally speaking, your best bet, then, is to start over with a
> > modern MTA's modern default config.
> >
> > If you _happen_ to be in the mood for considering an MTA switch, the
> > current best-practices choice is Postfix. (I do not use Postfix,
> > but rather Exim4. Were I to choose a new MTA, it would be Postfix,
> > but it doesn't have sufficiently compelling advantages to justify the
> > pain of switching.)
> >
>
> It's just an issue of inertial. A new MTA means learning a bunch of new
> things.
> In this case though, the problem is that the mail is actually addressed
> to the
> mailing list but my name is being spoofed on the from line.

Are you implementing SPF (publishing an SPF RR in your domain's DNS, and
then checking that RR in your MTA when it receives mail)? (It's
possible that I might have slightly misunderstood your question, the
first time. Unfortunately, I'm short on sleep at the moment.)

The purpose of SPF is to ensure that nobody can, ever again, conduct a
believable "Joe Job"[0] of a reputable domain. However, it works only if
you bother to publish a record that people can check -- and your MTA can
take advantage of it only if you have code to do so, there.

Making for a moment the assumption that you're talking about mailing
lists on domain mrbrklyn.com:

:r! dig -t txt mrbrklyn.com +short
[Returns null.]

Nope, it appears that you have not _even_ bothered to create an SPF RR.


To review, an SPF RR (tucked away into the catch-all "TXT" record type,
for lack of a dedicated RR from the IETF process) declares
(paraphrasing) that "This roster of IPs, and these alone, should be
regarded as authorised MXes for the cited domain. If you receive mail
from any IP not identified here, please assume the mail is forged."

linuxmafia.com's SPF RR:

:r! dig -t txt linuxmafia.com +short
"v=spf1 a mx -all"

Unpacking that syntax:
"v=spf1" => This record implements v. 1 of the SPF spec
"a" => Use the domain's "a" record for verification.
"mx" => Alternatively, use the "mx" record for verification.
"-all" => Hardfail check, if the IP doesn't match either of the foregoing.

Further details at: http://www.zytrax.com/books/dns/ch9/spf.html


So, basically, my DNS is informing the world that, if mail doesn't
arrive from IP 198.144.195.186 or from my published MX host (which is
currently mapped to the same thing, resolving via the MX-referenced A
record to IP 198.144.195.186), then it should be regarded as
conclusively forged.

Publishing a syntactically correct SPF RR is the easy part, and is
greatly in the interest of any domain owner to do, completely without
regard to whether one does anything else -- in part because it's
dead-simple and a one-time task. (You _should_ also have an explicit MX
record, Ruben! I've told you this before.) The more-difficult part is
integrating SPF-_checking_ into an MTA.

I have no relevant experience whatsoever in doing that with sendmail
(because sendmail's been gone from my life for a decade), but
Web-searching quickly finds at least one way to do it. There may be
more:
http://www.brandonhutchinson.com/Installing_Milter-SPF_with_Sendmail.html


[0] See the "Joe-job" entries on http://linuxmafia.com/kb/Mail/ for the
context and history of this term. People tend not to use the term "Yuri
Rutman" in their anecdotes about the invention of that particular form
of Internet abuse, because Rutman threatens and harrasses people who
talk about it. (You'll notice that Rutman apparently even harrassed
Google into expunging some of the evidence from Google Groups, nee
DejaNews.)

[1] I just read in a Feb. 2007 mailing list posting that IETF did
eventually approve a new RR for SPF, and BIND 9.4.0 and later supports
it. http://www.gossamer-threads.com/lists/spf/deployment/30942




--------------080401010407080508080804--

  1. 2008-12-01 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [NYLXS - HANGOUT] [Fwd: Tier 4 Support position available]
  2. 2008-12-02 Ruben Safir <ruben-at-mrbrklyn.com> Re: R: Re: [NYLXS - HANGOUT] NYLXS Installfest: Tuesday Evening: Dec 022008 Brooklyn
  3. 2008-12-02 Ruben Safir <ruben-at-mrbrklyn.com> Re: [NYLXS - HANGOUT] Installfest Priminary Schedule
  4. 2008-12-02 Ruben Safir <ruben-at-mrbrklyn.com> Re: [NYLXS - HANGOUT] NYLXS Installfest: Tuesday Evening: Dec 02 2008 Brooklyn
  5. 2008-12-03 Ruben Safir <ruben-at-mrbrklyn.com> Re: [NYLXS - HANGOUT] Free Software Contest
  6. 2008-12-03 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [NYLXS - HANGOUT] Free Software Contest
  7. 2008-12-04 Ruben Safir <ruben-at-mrbrklyn.com> Re: [NYLXS - HANGOUT] Free Software Contest
  8. 2008-12-04 mlr52-at-michaellrichardson.com RE: [NYLXS - HANGOUT] MTA RIPPOFF
  9. 2008-12-04 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [NYLXS - HANGOUT] MTA RIPPOFF
  10. 2008-12-05 Ruben Safir <ruben-at-mrbrklyn.com> Re: [NYLXS - HANGOUT] MTA RIPPOFF
  11. 2008-12-05 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [NYLXS - HANGOUT] [Monique.Hughes-at-gpj.com: CommunityOne Call for Participation]
  12. 2008-12-06 Amy Coleman <acoleman-at-mrbrklyn.com> Re: [NYLXS - HANGOUT] Installfest Priminary Schedule
  13. 2008-12-10 Amy Coleman <acoleman-at-mrbrklyn.com> Re: [NYLXS - HANGOUT] crazy women on the prowl
  14. 2008-12-10 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [NYLXS - HANGOUT] crazy women on the prowl
  15. 2008-12-11 swd <sderrick-at-optonline.net> Subject: [NYLXS - HANGOUT] Looooong Island Rail Road & Linux
  16. 2008-12-11 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [NYLXS - HANGOUT] [nyc-at-workatjelly.com: Jelly in Brooklyn this Friday, 12/12]
  17. 2008-12-12 From: "Michael L. Richardson" <mlr52-at-michaellrichardson.com> Re: [NYLXS - HANGOUT] [Fwd: New Mandriva Flash 2009 for the holiday
  18. 2008-12-12 Ruben Safir <ruben-at-mrbrklyn.com> Re: [NYLXS - HANGOUT] [Fwd: New Mandriva Flash 2009 for the holiday season]
  19. 2008-12-12 Ron Guerin <ron-at-vnetworx.net> Re: [NYLXS - HANGOUT] [malmonte-at-searchedp.com: PERL Developer]
  20. 2008-12-12 From: "Michael L. Richardson" <mlr52-at-michaellrichardson.com> Subject: [NYLXS - HANGOUT] [Fwd: New Mandriva Flash 2009 for the holiday season]
  21. 2008-12-12 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [NYLXS - HANGOUT] [malmonte-at-searchedp.com: PERL Developer]
  22. 2008-12-14 Amy Coleman <acoleman-at-mrbrklyn.com> Re: [NYLXS - HANGOUT] Freedom-IT this year
  23. 2008-12-14 Ruben Safir <ruben-at-mrbrklyn.com> Re: [NYLXS - HANGOUT] Freedom-IT this year
  24. 2008-12-14 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [NYLXS - HANGOUT] Freedom-IT this year
  25. 2008-12-15 Ruben Safir <ruben-at-mrbrklyn.com> Re: [NYLXS - HANGOUT] Dear (ruben-at-mrbrklyn.com) December 87% OFF!
  26. 2008-12-15 From: "Tameek" <tameek-at-gmail.com> Re: [NYLXS - HANGOUT] Dear (ruben-at-mrbrklyn.com) December 87% OFF!
  27. 2008-12-15 Ruben Safir <ruben-at-mrbrklyn.com> Re: [NYLXS - HANGOUT] tracking mail
  28. 2008-12-15 GUCCI <ruben-at-mrbrklyn.com> Subject: [NYLXS - HANGOUT] Dear (ruben-at-mrbrklyn.com) December 87% OFF!
  29. 2008-12-15 GUCCI <ruben-at-mrbrklyn.com> Subject: [NYLXS - HANGOUT] Dear (ruben-at-mrbrklyn.com) December 87% OFF!
  30. 2008-12-15 GUCCI <ruben-at-mrbrklyn.com> Subject: [NYLXS - HANGOUT] Dear (ruben-at-mrbrklyn.com) December 87% OFF!
  31. 2008-12-15 From: <ruben-at-mrbrklyn.com> Subject: [NYLXS - HANGOUT] Discount ID: 6104
  32. 2008-12-15 From: <ruben-at-mrbrklyn.com> Subject: [NYLXS - HANGOUT] Discount ID: 6657
  33. 2008-12-15 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [NYLXS - HANGOUT] tracking mail
  34. 2008-12-16 Ron Guerin <ron-at-vnetworx.net> Re: [NYLXS - HANGOUT] tracking mail
  35. 2008-12-16 From: "Michael L. Richardson" <mlr52-at-michaellrichardson.com> Re: [NYLXS - HANGOUT] tracking mail
  36. 2008-12-16 Ron Guerin <ron-at-vnetworx.net> Re: [NYLXS - HANGOUT] tracking mail
  37. 2008-12-16 From: <ruben-at-mrbrklyn.com> Subject: [NYLXS - HANGOUT] Discount ID: 0732
  38. 2008-12-16 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [NYLXS - HANGOUT] Xorg Wide Screen
  39. 2008-12-17 Ruben Safir <ruben-at-mrbrklyn.com> Re: [NYLXS - HANGOUT] tracking mail
  40. 2008-12-17 Ruben Safir <ruben-at-mrbrklyn.com> Re: [NYLXS - HANGOUT] tracking mail
  41. 2008-12-17 From: "Michael L. Richardson" <mlr52-at-michaellrichardson.com> Re: [NYLXS - HANGOUT] tracking mail
  42. 2008-12-17 Ron Guerin <ron-at-vnetworx.net> Re: [NYLXS - HANGOUT] tracking mail
  43. 2008-12-17 GUCCI <ruben-at-mrbrklyn.com> Subject: [NYLXS - HANGOUT] Dear (ruben-at-mrbrklyn.com) December 87% OFF!
  44. 2008-12-17 GUCCI <ruben-at-mrbrklyn.com> Subject: [NYLXS - HANGOUT] Dear (ruben-at-mrbrklyn.com) December 87% OFF!
  45. 2008-12-17 GUCCI <ruben-at-mrbrklyn.com> Subject: [NYLXS - HANGOUT] Dear (ruben-at-mrbrklyn.com) December 87% OFF!
  46. 2008-12-17 From: <ruben-at-mrbrklyn.com> Subject: [NYLXS - HANGOUT] Discount ID: 3732
  47. 2008-12-17 From: <ruben-at-mrbrklyn.com> Subject: [NYLXS - HANGOUT] Discount ID: 5215
  48. 2008-12-17 From: "Michael L. Richardson" <mlr52-at-michaellrichardson.com> Subject: [NYLXS - HANGOUT] Microsoft issuing emergency fix for browser flaw
  49. 2008-12-17 Mark Halegua <phantom21-at-mindspring.com> Subject: [NYLXS - HANGOUT] Problems with Groklaw?
  50. 2008-12-18 Ruben Safir <mrbrklyn-at-panix.com> Re: [NYLXS - HANGOUT] tracking mail
  51. 2008-12-18 GUCCI <ruben-at-mrbrklyn.com> Subject: [NYLXS - HANGOUT] Dear (ruben-at-mrbrklyn.com) December 84% OFF!
  52. 2008-12-18 From: <ruben-at-mrbrklyn.com> Subject: [NYLXS - HANGOUT] Discount ID: 4440
  53. 2008-12-18 From: <ruben-at-mrbrklyn.com> Subject: [NYLXS - HANGOUT] Discount ID: 9598
  54. 2008-12-18 From: "Michael L. Richardson" <mlr52-at-michaellrichardson.com> Subject: [NYLXS - HANGOUT] [Fwd: [kde-announce] KDE 4.2 Beta 2 Released]
  55. 2008-12-19 Ron Guerin <ron-at-vnetworx.net> Re: [NYLXS - HANGOUT] tracking mail
  56. 2008-12-19 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [NYLXS - HANGOUT] [Fwd: Re: admin question]
  57. 2008-12-21 Amy Coleman <acoleman-at-mrbrklyn.com> Subject: [NYLXS - HANGOUT] Happy Hanukah!
  58. 2008-12-22 Kevin Mark <kevin.mark-at-verizon.net> Re: [NYLXS - HANGOUT] Happy Hanukah!
  59. 2008-12-23 From: "Beau Gould" <bg-at-capitalmarketsp.com> Subject: [NYLXS - HANGOUT] [JOB] Linux Geek, NYC | 90-100k
  60. 2008-12-25 mlr52-at-michaellrichardson.com RE: [NYLXS - HANGOUT] Merry Christmas Everyone!
  61. 2008-12-25 Amy Coleman <acoleman-at-mrbrklyn.com> Subject: [NYLXS - HANGOUT] Merry Christmas Everyone!
  62. 2008-12-29 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [NYLXS - HANGOUT] Tim Wilcox coming in for a few days
  63. 2008-12-30 Ruben Safir <ruben-at-mrbrklyn.com> Re: [NYLXS - HANGOUT] Happy Hanukah!
  64. 2008-12-30 Amy Coleman <acoleman-at-mrbrklyn.com> Re: [NYLXS - HANGOUT] Tim Wilcox coming in for a few days
  65. 2008-12-30 Ruben Safir <ruben-at-mrbrklyn.com> Re: [NYLXS - HANGOUT] Tim Wilcox coming in for a few days

NYLXS are Do'ers and the first step of Doing is Joining! Join NYLXS and make a difference in your community today!