Gentoo Archives: gentoo-project

From: Michael Orlitzky <mjo@g.o>
To: gentoo-project@l.g.o
Subject: Re: [gentoo-project] Evidence of idella4's damage to Gentoo, please
Date: Mon, 05 Dec 2016 17:03:08
Message-Id: cde26e35-bca2-72d8-1db8-db8ef01432fd@gentoo.org
In Reply to: Re: [gentoo-project] Evidence of idella4's damage to Gentoo, please by Pacho Ramos
1 On 12/05/2016 11:50 AM, Pacho Ramos wrote:
2 >>
3 >> You need to ensure your sending it as me to me. But even if you
4 >> repeat, I
5 >> lowered the threshold for scoring. It should be rejected now.
6 >>
7 >
8 > Can we please try to stop derailing the mail threads?
9
10 Sorry... my original point was that this retarded rant about our mail
11 servers accepting spoofed "From:" headers is unfounded.
12
13 The same message still goes through with a forged "From" header:
14
15 $ sendmail -f michael@××××××××.com wlt-ml@××××××.com < wlt.msg
16
17 Dec 5 11:52:53 mail2 postfix/smtp[19091]: 3tXVxJ0Dzbz15Rx:
18 to=<wlt-ml@××××××.com>,
19 relay=mail1.obsidian-studios.com[173.230.135.215]:25, delay=450,
20 delays=448/0.03/0.27/1.1, dsn=2.0.0, status=sent (250 ok 1480956773 qp
21 18788)
22
23 Something is not "off" with our mail servers, and there is currently no
24 way to prevent "From" spoofing without significant collateral damage.

Replies

Subject Author
[gentoo-project] Infra response re SPF. "Robin H. Johnson" <robbat2@g.o>