republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Blocking Port 25 Traffic » Thanks Idiots!
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Post a:
Post a:
Comcast SMTP not needed here? »
« Other port 25 checks  

Steve
I'm a PC, so shut up
Consultant
join:2001-03-10
Yorba Linda, CA

Re: Thanks Idiots!

said by Camelot One See Profile:
I am in the same boat. This will prevent all users from being able to say, send email from their work address at home. Anyone with a Road Runner accoun tfor example can only send email from their rr email address.

Stupid. Just plain stupid.
What's stupid is that Road Runner even considers the "From" address when relaying email - this is no kind of security (I understand Verizon did this too, perhaps they still do).

If the source IP address is from a "trusted" source - from within RoadRunner's own network - there is no good reason for disallowing users to include any From: address they wish, including valid work addresses.

An ISP that blocks outbound 25/tcp and limits users to the @isp.net From address is doing a bad thing.

Steve
--
Stephen J. Friedl * Security Consultant * Tustin, California USA * my web site

keith2468
Premium,MVM
join:2001-02-03
Winnipeg, MB

That is what REPLY-TO/reply address is for

quote:
I am in the same boat. This will prevent all users from being able to say, send email from their work address at home. Anyone with a Road Runner accoun tfor example can only send email from their rr email address.
That is what the REPLY-TO (in OE accounts, the "reply address") is for.

SENT-BY (FROM or, in OE accounts, the "email address") is formally supposed to be the email address on the ISP the computer is actually on. As noted by another poster, only a few ISPs check this.

ISPs should not be limiting the REPLY-TO (unless maybe the customer has been a problem), but to follow the original intent of the standards, they all should have been limiting the SENT-BY.

My personal feeling is that ideally such filtering (port 25, spam, email virus) should a user configurable, and default to filtering for new accounts.

I think the problem is technical:
1. It increases overhead to add a bunch of individual IP addresses to port blocking rules in the router.
2. There is a bit of manual effort involved in updating the rules for individual customers.

It isn't dumb users that are responsible for "reduced functionality", it is the hackers and spammers who exploit them.

Steve
I'm a PC, so shut up
Consultant
join:2001-03-10
Yorba Linda, CA

Re: That is what REPLY-TO/reply address is for

said by keith2468 See Profile:
That is what the REPLY-TO (in OE accounts, the "reply address") is for.

SENT-BY (FROM or, in OE accounts, the "email address") is formally supposed to be the email address on the ISP the computer is actually on.
Says who?

This premise cannot possibly hold water, and it's hard to even know where to start.

First, and most broadly, your online identity is anything you want it to be, and in my book, you "are" any email address to which you have valid access to the mailbox. This gives me probably a half a dozen email addresses, none of which is the "real" address unless I say one of them is.

Second, many people purchase IP services with the sole intent of routing IP packets, and they do not buy into the additional services (email, web space, home page) that the ISP may offer. I have Pac*Bell DSL, but as far as I know I don't have a @pacbell.net email address.

Finally, there is no required connection between "email address" and "physical location" - otherwise this premise would play havoc with the salesman on the road: does he get a new "Sent-From" email address in every hotel?

Steve
--
Stephen J. Friedl * Security Consultant * Tustin, California USA * my web site
Forums » Blocking Port 25 TrafficComcast SMTP not needed here? »
« Other port 25 checks  


Friday, 04-Dec 22:58:44 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [163] Comcast Releasing Promised Usage Meter
· [145] Avast Antivirus Has Gone Mad
· [126] Comcast Makes NBC Universal Acquisition Official
· [104] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [101] Google Invades ISP, OpenDNS Turf With Google Public DNS
· [83] FCC Ponders Moving From PSTN To IP Voice
· [81] Latest Consumer Reports Survey Not Kind To AT&T
· [74] Sprint Defuses GPS Privacy Media Bomb
· [70] Baltimore To Ban Lazy Cable Installs
· [69] The Bandwidth Hog Does Not Exist
Most people now reading
· False positive in Avast! or is it real? [Security]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Farewell [Bell Canada]
· DNS options, what are YOU using? [TekSavvy]
· Windows 7 boot manager editing questions [Microsoft Help]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· Evading throttling with uTP / uTorrent 1.9a [TekSavvy]
· IPComms Free DIDs now with sip registration maybe?? [VOIP Tech Chat]
· [Snow Leopard] NFS Mounts - no more Directory Utility [All Things Macintosh]
· [Unlock] TUTORIAL: VONAGE WRTP54G/RTP300 WITH 5.01.04 [VOIP Tech Chat]