Full Disclosure mailing list archives

Re: VeriSign's fake SMTP server for SiteFinder


From: "Damian Gerow" <damian () sentex net>
Date: Mon, 22 Sep 2003 18:31:56 -0400

On Mon, 22 Sep 2003, Pamela Patterson wrote:
If they had no mail server there at all, mail sent to non-existent
domains would sit in limbo as the upstream machine tried to deliver it
to the Verisign machine.  How many times it would try and how long it
would wait would depend on the MTA configuration, but it could be days. 
If email sent to misspelled domains took 5 days (the sendmail default)
to bounce due to Verisign's domain squatting, people would be very upset

People /are/ very upset.  Even though they have implemented a rejecting
mail server.

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: