1. Please take a little time for this simple survey! Thank you for participating!
    Dismiss Notice

qmail security

Discussion in 'Plesk for Linux - 8.x and Older' started by Osmolovsky, Jun 24, 2005.

  1. Osmolovsky

    Osmolovsky Guest

    0
     
    anoter question.

    if client buy hosting for spam purposes (he dont say about it ^) and make spam sending from his local account (127.0.0.1:25) by scripts or connect to smtp from his machine.

    How i can detect trying to send spam's and stop it automaticaly?

    I think one of solution is control "number of messges/hour" but dont uderstand how to realize that. And how to realize that on separate client.

    Any ideas?

    ps. sry for my English ^)
     
  2. hardweb

    hardweb Guest

    0
     
    You can do this only with a queue wrapper which drops emails based on an IP history. Such feature does not exist in the standard qmail. But technically it can be done.
     
  3. atomicturtle

    atomicturtle Golden Pleskian

    29
     
    Joined:
    Nov 20, 2002
    Messages:
    2,110
    Likes Received:
    7
    Location:
    Washington, DC
    my qmail-scanner rpm implements detecting spam on both incoming, and outgoing mail through the MTA on the server.
     
  4. Osmolovsky

    Osmolovsky Guest

    0
     
    Can you explain more in detail?
     
  5. atomicturtle

    atomicturtle Golden Pleskian

    29
     
    Joined:
    Nov 20, 2002
    Messages:
    2,110
    Likes Received:
    7
    Location:
    Washington, DC
    Yep, just install qmail-scanner and you're done :p
     
  6. jshanley

    jshanley Guest

    0
     
    What hardweb means is, Plesk does not keep track of how many emails an account has sent over any given period of time. The qmail wrapper script would be placed where qmail-send usually is, and would keep track of how many emails a particular account has sent, say over the last hour.

    Then you'd configure the wrapper script to say "If someone has sent more than 500 emails in the last hour, reject any additional mail from them"

    However, you'd have to be careful not to block legitimate users that send out thousands of emails on a legitimate email list (using mailman or whatever).

    Also, I'm not aware of any that work with plesk's custom structure. Doesn't mean they dont exist, though.
     
Loading...