Last modified: 2014-11-17 11:06:00 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T67629, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 65629 - Harden mail server against incoming spam
Harden mail server against incoming spam
Status: NEW
Product: Wikimedia Labs
Classification: Unclassified
tools (Other open bugs)
unspecified
All All
: Unprioritized enhancement
: ---
Assigned To: Marc A. Pelletier
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2014-05-22 13:40 UTC by Tim Landscheidt
Modified: 2014-11-17 11:06 UTC (History)
4 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description Tim Landscheidt 2014-05-22 13:40:12 UTC
Currently, the mail queue has a handful of outgoing bounces that relate to mails to user@tools.wmflabs.org (an existing mail address) that were tried to be forwarded to that user's address, but didn't succeed.

The problem with that is that the recipients of those bounces (i. e. the senders of the incoming mails) are from non-existing domains and/or users.

The mails are in Chinese and contain spreadsheet attachments.  User "user" seems to be Chinese, but my gut tells me that this is spam.

So before we become the target of more of that, we should harden the mail server so that it only accepts mail from domains that actually resolve (and/or other similar anti-spam best practices for exim).
Comment 1 Liangent 2014-05-28 16:59:59 UTC
(In reply to Tim Landscheidt from comment #0)
> The mails are in Chinese and contain spreadsheet attachments.  User "user"
> seems to be Chinese, but my gut tells me that this is spam.

Confirming.

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links