git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [OT] Re: Feature request - Subtree checkouts

From
JTJimmy Tang <jtang@tchpc.tcd.ie>
Date
Apr 12, 2007, 09:55 UTC
Message-ID
<20070412095519.GB26763@vual.tchpc.tcd.ie>
In-Reply-To
<Pine.LNX.4.64.0704101414330.15823@blackbox.fnordora.org>
On Tue, Apr 10, 2007 at 02:33:54PM -0700, alan wrote:
Show 26 quoted lines
> >
> >For example, I will personally never see email that comes directly to my
> >email address though an open mail relay *or* from something that appears
> >to be just a random botnet PC (I forget the exact rule, since I'm hapily
> >ignorant of MIS, but I think it boils down to requiring a good reverse DNS
> >lookup).
> 
> Depending on your definition of "good".
> 
> I run my mail server off my DSL line.  I prefer having control over my 
> mail server instead of being chained to what my ISP provides.  (The 
> problems of having been a sysadmin for way too many years.) I don't have 
> control over the reverse ip address, but I do over my DNS resolution. 
> (Well, most of it. A couple domains are sitting on really old dns servers 
> from years past.)
> 
> >That's getting much more common. Most spam is done through botnets, and
> >they still try to do the direct-to-port-25 thing, exactly because if you
> >go through a *real* SMTP host, your ISP will generally shut you down
> >pretty quickly if you're spamming.
> 
> Which makes Greylisting a useful tool.  However, some people define a 
> "real SMTP host" as being the one your ISP provides and no other.  No 
> matter how good your OS or how stringent your rulesets for sending mail 
> are.
> 

greylisting unfortunately requires "some maintenance" to keep it going well, and it also breaks some mail appliances and probably some MTA's that are completely compliant in retrying to send mails.

another tactic which is probably just as good if not better than greylisting is "nolisting", that is to have your primary mx point to a non-existant machine with a real ip-address and dns entries (or even a machine with a firewall that runs iptables that blackholes or does funky stuff to anything coming in on port 25 and then just drops the connections).

if the remote end is a compliant MTA it will failover to the secondary mx which is a real machine that receives mail. but it probably suffers from the same problem of mail appliances not being completely compliant to the specs on how MTA's should work.

nolisting offers almost as good effects as greylisting without the hassle of maintaining a list.

Jimmy.
-- 
Jimmy Tang
Trinity Centre for High Performance Computing,
Lloyd Building, Trinity College Dublin, Dublin 2, Ireland.
http://www.tchpc.tcd.ie/ | http://www.tchpc.tcd.ie/~jtang
Previous: David LangNext: Robin H. Johnson
Message 11 of 15 in “Feature request - Subtree checkouts”
  1. Robin H. JohnsonApr 10, 2007
  2. Shawn O. PearceApr 10, 2007
  3. Junio C HamanoApr 10, 2007
  4. Linus TorvaldsApr 10, 2007
  5. [OT] Re: Feature request - Subtree checkoutsalan, Apr 10, 2007
  6. Linus TorvaldsApr 10, 2007
  7. alanApr 10, 2007
  8. Christer WeinigelApr 10, 2007
  9. alanApr 10, 2007
  10. David LangApr 10, 2007
  11. Jimmy TangApr 12, 2007
  12. Robin H. JohnsonApr 10, 2007
  13. Robin H. JohnsonApr 10, 2007
  14. Shawn O. PearceApr 10, 2007
  15. Johannes SchindelinApr 14, 2007

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.