Syndicate

Syndicate content

Flattr


Flattr this

If you like this, you can use flattr. ;)

Imprint

About
eMail: wishinet at gmail . com
PGP ID: 0xCCCA5E74

Jabber: wishi@jabber.ccc.de

Internet Protocols

Postfix troubleshooting - a security nightmare

Why to hate typical Unix mailserver setups

I hate that stuff - and it's not that Postfix in particular sucks. But integrating with Postfix is absurd. Surely it works, and as long as it works nobody changes that stuff on how it's designed.


Ohne Titel.png

Even deploying an SSL/TLS setup is challenging. But no, you also need to install proper authentication. Locally, Postfix (for unknown reasons) is chrooted. People think that this is a security feature.

A practically secure mail setup - counter spammers with Linux mail-servers

Who needs this?

Bild 1.JPG
Yay, free mails in a sustaining setup!

This is a tutorial on how to practically setup a relatively secure mail-server.

It's supposed to be as minimal as reasonable nowadays, and for a small amount of users (standard root server, max. ~20 mail-users at once). Without a real DB backend. It doesn't scale business-needs, however it's supposed to be extendable.

The reference system this setup works with is a Debian GNU Linux with:

  • Maildrop - instead of Procmail for more flexible filter rulesets
  • Postfix and Postfix-pcre ~ 2.7

PyQt and a SSH upload droplet

Modern GUIs need Drag and Drop

The following is an example for a drag & drop action with PyQt4. It uses paramiko for SSH interactions. I'm well aware that it won't work on Windows that way. But that's a Windows problem. I'm also well aware that there's a password in this file. Give it a try.
The source is at GitHub. The indention seems to be broken there. But that's a GitHub problem. It seems to be broken here, too. But that's a Drupal problem. ;). Actually it isn't even a problem.

Just the imports. The os module is necessary if you want paramiko to use your private ssh-key. The sys module is needed due argv:

  1. #ff7700;font-weight:bold;">import #dc143c;">sys
  2. #ff7700;font-weight:bold;">import paramiko #808080; font-style: italic;"># for ssh
  3. #ff7700;font-weight:bold;">import #dc143c;">os  
  4. #ff7700;font-weight:bold;">from PyQt4 #ff7700;font-weight:bold;">import QtGui, QtCore

mutt AND Gmail AND imaps - easy new setup

mutt meets the cloud

mutt is a pretty decent terminal based mail-client. It reliably runs on almost every platform, is RFC conform by default, lightweight, fast, extremely versatile and sweet as leet. In order to take advantage of all the kewl features of Gmail many people use heavyweight mail-clients like Mail.app (>300 MB), Outlook (infinite waste of space and time), or Thunderbird (the compromise).
In the past mutt was just a MUA, but since ~ 1.5 there's a useable smtp, imap and pop3 backend. In the following I hacked mutt to sync with multiple Gmail imap accounts to use the great filters and infinite space - from a terminal. Just mutt and Gmail.

Blackhat 2008 video archives are open

About IT security and more


A63965B6-4312-4D34-8FF8-E27D37A7C14A.jpg
hey guess what: the trojan horse has got a black hat :)

The conference material at BH is always kewl. Attending to this con is highly expensive because it's far away - in my case. Well... here's the material publicly available. For personal entertainment: Follow this link.

Highlights for the moment Read more »

Greetings from Chinopa - about the art of indirect restrictions

958AD525-40C0-47B3-B19B-96818CC7E379.jpg
old DDR customs official's watchtower


There's no censorship in free democratic states?

The Federal Republic of Germany begins to restrict information access for its citizens (again) - in the uttermost dubious and ineffective way. Due consistent lack of technical knowledge and unnatural high resistance against arguments freedom of speech is about to cease to exist. Within the borders where some time ago poets, thinkers and libertines had a right to simply express themselves, those troublemakers nowadays are to be silenced.

So fast - so weekly: a week of reading


2B779D97-6894-45EC-935C-6EB677B270DE.jpg
funny japanese wireless toilet control (source)

I just thought - because there's enough to read for everybody in IT security at the moment: keep this short and just list the stuff with some tiny little annotations.

Save the nature. Don't print this!


I provide textual exports for every blog entry. However let's save the nature together. The nature is everything around us. Every being should be respected. Save the nature - don't print too much.


Die Umgehung dieser Ausdrucksperre ist nach § 95a UrhG verboten!
Inhaltlich Verantwortlicher gemäß § 10 Absatz 3 MDStV: Marius Ciepluch - Anschrift via eMail. Die eMail Adresse entnehmen sie dem Impresseum dieser englischsprachigen Seite.
Aus Datenschutzgründen habe ich weder offiziellen noch behördlichen Schriftverkehr via eMail. Dazu ist die postalische, beim Dienstleister hinterlegte, Anschrift zu verwenden.

Datenerfassung

Es werden keine personenbezogenen Daten erfasst. Logdaten werden anonymisiert.