Compare cert salaries and plan your next career move
mikedisd2 wrote: » I've been left to pickup a half implemented anti-spam mail filter called ORF that sits on a DMZ Windows stand-alone along with IMSS (don't say it, it's not changing). Currently the IP Address allocated to ORF is blacklisted on Backscatterer.org and I'm required to resolve it as it shows up in the morning checks as an alert. Backscatterer.org says the blacklist will expire in a month but the issue is why it was there in the first place. ORF's default configuration is to send an NDR upon rejection of spam but I've felt it's best practice to drop spam, not send a bounceback. ORF has a warning that doing this breaches Internet RFC. Any word on this? What do people do in other organisations? Do you drop spam or or do you return 10^n "5.1.1 error invalid recipient" messages, possibly to unwitting spoofed addresses?
it_consultant wrote: » Most anti spam systems I use do not do a silent drop but do not send a NDR. When a server is rejected the sending SMTP server receives an enhanced status code which is relayed to the sender by the sending SMTP server. That way you can be mainly in compliance with IEEE but you are also not sending out backscatter. An enhanced status code normally includes the reason for the drop, like being on a blacklist, malformed mail headers, non-existent recipients, policy violation etc.
Everyone wrote: » You should be able to get your domain off the blacklist before it expires... it should tell you exactly why you got blacklisted.
To track down what happened investigate your smtplogs near 27.06.2011 12:50 CEST +/-1 minute. ... Reading your logs carefully it shouldn't be a big deal to figure out what caused or renewed your listing.
mikedisd2 wrote: » Another thing I intended to do was AD authentication. Again, I thought this would be standard practice to instantly reject non-existing addresses. It'll mean opening LDAP ports on the DMZ/Internal firewall. Is anyone disinclined to do this?
Everyone wrote: » Sounds like you inherited someone else's mess. As long as the rule only allows it between your mail gateways and a domain controller, you should be fine. Use SSL LDAP if you can (port 636).
A total of 148 Impacts were detected during this listing. Last was 30.06.2011 16:38 CEST +/- 1 minute. Earliest date this IP can expire is 28.07.2011 16:38 CEST.
mikedisd2 wrote: » Well my blacklist is renewing everyday, even though I've switched off the ORF service. There's no logs to check at the dates being generated. This is suss. EDIT: Just realised this is a VM and that the 2x network cards don't seem to be working independantly. The ORF NIC is constantly sending packets; may need to analyse the wire.
Compare salaries for top cybersecurity certifications. Free download for TechExams community.