exim: Don't do sender verification by callout.
authorMatthijs Kooijman <matthijs@stdin.nl>
Mon, 4 May 2009 12:58:56 +0000 (14:58 +0200)
committerMatthijs Kooijman <matthijs@stdin.nl>
Mon, 4 May 2009 12:58:56 +0000 (14:58 +0200)
Doing callouts puts extra resource pressure on the called server. Since
the sender address will be forged in a lot of cases anyway, this won't
really help us and can be used in a DDOS attack on some server. See
http://www.backscatterer.org/index.php?target=sendercallouts


No differences found