Opened 12 years ago

Closed 10 years ago

#194 closed defect (fixed)

Disable mail to *@scripts-vhosts.mit.edu

Reported by: andersk Owned by:
Priority: major Milestone:
Component: mail Keywords:
Cc:

Description

Many sendmail installations, including MIT’s, canonicalize eviluser@… to eviluser@…, which currently works like eviluser@…. People shouldn’t be able to get an email address at a domain that isn’t theirs without permission, so we should disable mail received at scripts-vhosts.mit.edu.

Change History (3)

comment:1 Changed 11 years ago by ezyang

  • Priority changed from normal to major

comment:2 Changed 10 years ago by adehnert

This canonicalization is done by the remote server, not the receiving MTA, right? (So "patch postfix to remove this behavior" is not an option.)

As I recall, there were some sort of backwards-compatibility concerns about doing this. Does anybody remember specifics?

comment:3 Changed 10 years ago by achernya

  • Resolution set to fixed
  • Status changed from new to closed

Anders fixed this in r2375.

Note: See TracTickets for help on using tickets.