Re: locking down squirrel mail

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



>>>  So far I've added a captcha, but this doesn't seem to help as much as
>>> you'd think.
>>>
>>
>> Make sure the backend you've chosen is a good one.  Some of them are
>> relatively simple to hack.  Note also you can use it in combination
>> with the User Information plugin to restrict the country of origin.
>>
>>
> The captcha is recaptcha.
>
> Added User Information plugin. I'll have to look into this one further.
>
>> You're trying to detect the problem by looking at emails that have
>> already been sent out - you should fight the problem earlier.  Install
>> the Squirrel Logger and/or Restrict Senders plugins which can watch
>> and optionally lock down accounts that start sending out large volumes
>> of messages, especially with lots of recipients.  You can also employ
>> outgoing spam filters in your MTA and/or rate-limit your senders in
>> the MTA.
>>
> True I am trying to track down the spammers after the fact, but there is
> also no, or limited, reasons for a user to be sending emails with an
> address other that their login especially using webmail. This is, of
> course, partially a policy decision.
>
> Already had Squirrel Logger install which helps greatly in spotting the
> spammers.
>
> Didn't know about Restrict Senders. Have installed this and configured
> it with what I think is reasonable settings. We'll have to wait and see
> what effect this has.
>
>> Then, turning off ability to edit email address in the configuration
>> should be sufficient (or even not that necessary).
>
> Which setting in which file do you mean? The one to which I already
> referred to or another one i've missed. (Too many email addresses :-) ).

$edit_identity
$edit_name

config/conf.pl ==> 4. General Options ==> 9. Allow...

> Would still like to remove some option pages as well. eg,
>>> to remove the settings for "Reply To" and "Email Address". However, I'm
>>> not having much luck removing the

The forced prefs settings you have should work on the main identities
option page.  If you set $edit_identity to false, the multiple
identities link will be gone.

>>> Multiple Identities:    Edit Advanced Identities (discards changes made
>>> on this form so far)
>>>
>>>

------------------------------------------------------------------------------
Crystal Reports - New Free Runtime and 30 Day Trial
Check out the new simplified licensign option that enables unlimited
royalty-free distribution of the report engine for externally facing 
server and web deployment.
http://p.sf.net/sfu/businessobjects
-----
squirrelmail-users mailing list
Posting guidelines: http://squirrelmail.org/postingguidelines
List address: squirrelmail-users@xxxxxxxxxxxxxxxxxxxxx
List archives: http://news.gmane.org/gmane.mail.squirrelmail.user
List info (subscribe/unsubscribe/change options): https://lists.sourceforge.net/lists/listinfo/squirrelmail-users


[Index of Archives]     [Video For Linux]     [Yosemite News]     [Yosemite Photos]     [gtk]     [KDE]     [Cyrus SASL]     [Gimp on Windows]     [Steve's Art]     [Webcams]

  Powered by Linux