[CentOS-devel] Spammer: Did we shut him down?

Wed Jan 28 20:55:33 UTC 2009
Hugo van der Kooij <hvdkooij at vanderkooij.org>

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

seth vidal wrote:
> On Wed, 2009-01-28 at 10:45 -0800, Scott Silva wrote:
>> But it also made the announce-list. I assumed the announce list was only
>> writable by a select few.
> 
> and the email came from lance at centos.org
> 
> lance at centos.org was one of the select few.

There is no SPF record for centos.org

If one can be added then this sort of fakes can be prevented. Anyone
using the centos.org domain in email should login to a centos.org server
to send out email that way.

I know it works because that is how I send out email from my own domain.
All family members need to use the central server as relay to send out
email with the family domain. And they can only authenticate using TLS
and SASL.

Hugo.


- --
hvdkooij at vanderkooij.org               http://hugo.vanderkooij.org/
PGP/GPG? Use: http://hugo.vanderkooij.org/0x58F19981.asc

	A: Yes.
	>Q: Are you sure?
	>>A: Because it reverses the logical flow of conversation.
	>>>Q: Why is top posting frowned upon?

Bored? Click on http://spamornot.org/ and rate those images.

Nid wyf yn y swyddfa ar hyn o bryd. Anfonwch unrhyw waith i'w gyfieithu.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org

iEYEARECAAYFAkmAxkQACgkQBvzDRVjxmYHORACghvMhTipp5+Y/0Yyf7CRXk8gx
im8AnArkugolVQc/ynsvv6eQBSEGaZBC
=+13T
-----END PGP SIGNATURE-----