Opened 11 years ago

Closed 9 years ago

#194 closed defect (fixed)

Disable mail to *@scripts-vhosts.mit.edu

Reported by: andersk Owned by:
Priority: major Milestone:
Component: mail Keywords:
Cc:

Description

Many sendmail installations, including MIT’s, canonicalize eviluser@… to eviluser@…, which currently works like eviluser@…. People shouldn’t be able to get an email address at a domain that isn’t theirs without permission, so we should disable mail received at scripts-vhosts.mit.edu.

Change History (3)

comment:1 Changed 10 years ago by ezyang

  • Priority changed from normal to major

comment:2 Changed 9 years ago by adehnert

This canonicalization is done by the remote server, not the receiving MTA, right? (So "patch postfix to remove this behavior" is not an option.)

As I recall, there were some sort of backwards-compatibility concerns about doing this. Does anybody remember specifics?

comment:3 Changed 9 years ago by achernya

  • Resolution set to fixed
  • Status changed from new to closed

Anders fixed this in r2375.

Note: See TracTickets for help on using tickets.