<<< Date Index >>>     <<< Thread Index >>>

Re: [Fwd: i am desperate]



On Sun, Feb 29, 2004 at 10:35:25AM +0000, Steve Kennedy wrote:
> On Sat, Feb 28, 2004 at 07:48:43PM -0800, Will Yardley wrote:
 
> > Perhaps the gbnet admins could block messages from outside /
> > non-authenticated clients sending HELO as mutt.org? That would probably
> > block this virus, as well as some spam as well.
> > ----- Forwarded message from roessler@xxxxxxxxxxxxxxxxxx -----
> > Received: from 82-37-77-190.cable.ubr02.dudl.blueyonder.co.uk (HELO 
> > mutt.org) (82.37.77.190)
> >   by ns.gbnet.net with SMTP; 29 Feb 2004 02:49:22 -0000
> > From: roessler at does-not-exist.org
> > To: mutt-dev at mutt.org
 
> Indeed there are traps, but this was sent from Mr Roessler ? Do we block
> every person who's on the list ? I don't think that would quite work.

The virus was sent "from" thomas, but I doubt Thomas's MTA sends HELO as
"mutt.org". I'm not suggesting blocking the address - just blocking smtp
clients that send HELO as mutt.org (I think that would likely not block
any legitimate mail, though I could be wrong).

-- 
"Since when is skepticism un-American?
Dissent's not treason but they talk like it's the same..."
(Sleater-Kinney - "Combat Rock")