Re: press: The Joe Job DoS attack


On Tue, Apr 06, 2004 at 22:37 +0300, Matti Aarnio wrote:

> > Developers and mail administrators are urged to secure their SMTP mail
> > services, as explained here (PDF). The fix is simple enough: don't send
> > the attachment part of non-delivery receipt; and send one email in
> > response to every mail failure, rather than one for every intended
> > recipient.
> I am somewhat dis-inclined not to return the attachment to the original
> sender..

IMHO - more interesting way is to have limit for maximum size of returned
message (automatic RET=HDR only for BIG messages).

