I use PopB4SMTP. Wouldn't it stand to reason that even if a client knew what IP to "spoof" in a packet to cause your server to log the IP need to know a login / pw? And if so, doesn't that make the risk moot?
Or, are we talking about something that may hi-jack your pop session via injection or the like? As much as I'd like to be, I'm not a guru on how one would go about spoofing the IP address and authenticating in order to fool ASSP. Am I missing something? Best, Chris Eric B. wrote: > "Micheal Espinola Jr" <[EMAIL PROTECTED]> wrote in message > news:[EMAIL PROTECTED] > >> Charles Marcus wrote: >> >>> I've never used it either, and would not do so, since it is supposedly a >>> security risk (not sure on the whys and hows). >>> >> Most likely because it could be tricked by IP spoofing known clients. >> > > Also because your MTA will allow any client from the same IP to connect for > a period of time after the IP has checked a POP account. So, if your PC is > behind a NAT and checking a public POP machine, any PC behind your NAT box > will have access to relaying email through the SMTP for a fixed amount of > time (sometimes 5 mins, sometimes 45mins). > > Eric > > > > > ------------------------------------------------------------------------- > Take Surveys. Earn Cash. Influence the Future of IT > Join SourceForge.net's Techsay panel and you'll get the chance to share your > opinions on IT & business topics through brief surveys - and earn cash > http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV > _______________________________________________ > Assp-user mailing list > Assp-user@lists.sourceforge.net > https://lists.sourceforge.net/lists/listinfo/assp-user > > ------------------------------------------------------------------------- Take Surveys. Earn Cash. Influence the Future of IT Join SourceForge.net's Techsay panel and you'll get the chance to share your opinions on IT & business topics through brief surveys - and earn cash http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV _______________________________________________ Assp-user mailing list Assp-user@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/assp-user