Re: [AMaViS-user] [SPAM] First public pre-release (-pre2) of

This is a discussion on Re: [AMaViS-user] [SPAM] First public pre-release (-pre2) of within the Amavis User forums, part of the Anti-Spam and Anti-Virus Related Forums category; Vincent, > > If using p0f-analyzer, please switch soon to a version of > > p0f-analyzer.pl as ...


Go Back   Usenet Forums > Anti-Spam and Anti-Virus Related Forums > Amavis User

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 01-24-2007
Mark Martinec
 
Posts: n/a
Default Re: [AMaViS-user] [SPAM] First public pre-release (-pre2) of

Vincent,

> > If using p0f-analyzer, please switch soon to a version of
> > p0f-analyzer.pl as supplied with 2.4.5-pre2 (or later).
> > It fixes an endless-loop in p0f-analyzer.pl which happens
> > if a p0f daemon crashes (piped to stdin of p0f-analyzer)
> > or is manually terminated without also terminating p0f-analyzer.
> > The fixed p0f-analyzer.pl may be (and should be) used
> > even with earlier versions of amavisd. Additionally,
> > it binds only to a loopback interface by default
> > (as some marginal security improvement).


> I run p0f-analyzer.pl on my MX host and amavisd-new on another host, is
> this a security problem because p0f-analyzer does not bind to loopback
> interface?


No, it is not a security problem, just nice to have.

There is already a restriction in p0f-analyzer.pl (the list @inet_acl)
which discards all requests not coming from 127.0.0.1 (or whatever
IP addresses are listed in @inet_acl).

What is important is that p0f-analyzer.pl does not enter a
tight loop (unnecessarily wasting resources) if it happens
that a p0f program (piped to it) would crash or is manually killed.

Mark

-------------------------------------------------------------------------
Take Surveys. Earn Cash. Influence the Future of IT
Join SourceForge.net's Techsay panel and you'll get the chance to share your
opinions on IT & business topics through brief surveys - and earn cash
http://www.techsay.com/default.php?p...rge&CID=DEVDEV
_______________________________________________
AMaViS-user mailing list
AMaViS-user@lists.sourceforge.net
https://lists.sourceforge.net/lists/...fo/amavis-user
AMaViS-FAQ:http://www.amavis.org/amavis-faq.php3
AMaViS-HowTos:http://www.amavis.org/howto/
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 10:18 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0