[Logwatch-Devel] Sendmail Unknown Users Patch

Erik Ogan erik@ogan.net
Fri, 04 Apr 2003 09:34:30 -0600


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Kenneth Porter wrote:
> I saw one of these last week. About every half hour I'd get hit by a
single
> message with a block of bogus target addresses, using a single sendmail
> connection. The relay was always the same. That suggests that you
could filter
> on the relay rather than the username.

	Indeed you could. Unfortunately, this is not an occasional
	thing for us, but a constant flood. The list of addresses
	rotates quickly enough (every few days) that I wanted a
	fallback to NOT show them by default in the report mailed
	to us, but only when we purposefully ask for it (as whem I
	re-run with detail set to 10)

	Unless you mean filter in logwatch based on relay....hmm,
	the display code already loops over the usernames...if I
	stored references...An excellent idea! (I'll play with it
	to see  if I can reduce the potential memory footprint...)

- -e

- --
Erik R. Ogan                                    Mercenary Developer
PGP Key:         http://erik.ogan.net/PGP.txt            0 o . _O-d
PGP Fingerprint: A3DB 678A 4737 32E7 F703  DC3A 6BFE 2BBC 4F41 A371

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQE+jaYFa/4rvE9Bo3ERAip+AJ9EvBlS/BMerjkBk+loYgMsCZbOfgCfX2Ng
sV+goqrd/AD1dXQySPeB0wg=
=nrp1
-----END PGP SIGNATURE-----