03-03-2005 07:40 AM
Does the nation know about the virtual gateway for bounce messages?
03-03-2005 02:23 PM
Decided to wait until IronPort had conversational LDAPaccept and then the NDR issue is gone, in my opinion. I just want to quit generating post conversational NDR's altogether! :)
03-03-2005 09:26 PM
Are you concerned about exposing your directory with conversational LDAP accept? It's a real threat. Someone can open a connection, and in 120 seconds have a list of 10,000 valid addresses at your company.
03-03-2005 09:39 PM
I am expecting IronPort to implement a form of DHAP (directory harvest attack prevention) to prevent this based on the number of invalid LDAP requestest per IP per hour, much like the current post conversational feature.
Basically a limit to the number of LDAPaccept failures per connection and/or a limit to the number of LDAPaccept failures per IP per hour. I would expect to implement a limit like 30 or so per hour. At that point a harvest attack would take quite some time.
Am I off in my thinking here?
03-25-2005 08:10 AM
My reason not to use virtual gateways for NDR bounce messages. When you do post conversational bounces you are going to be sending a fairly high level of emails to bogus or spoofed MAIL FROM: addresses (backscatter).
So with a virtual gateway you can route these out a dedicated IP address for NDRs.
My beef is using virtual gateways for your NDR bounce solution just hides the problem of lack of conversational bounces. You will still be sending a lot of backscatter garbage out, just now you don't really care if it gets blacklisted. If you don't care if is gets blacklist why send them at all?
I should really not be the one standing on this soapbox... Yes, I have been responsible for an insane amount of miss-directed/garbage NDRs, I'm trying to recover from this :)
Don't get me wrong I think virtual gateways are cool, just not as a NDR solution. They are great for multiple domains, marketing, etc.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide