I use PopB4SMTP. Wouldn't it stand to reason that even if a client knew 
what IP to "spoof" in a packet to cause your server to log the IP need 
to know a login / pw?  And if so, doesn't that make the risk moot?

Or, are we talking about something that may hi-jack your pop session via 
injection or the like?

As much as I'd like to be, I'm not a guru on how one would go about 
spoofing the IP address and authenticating in order to fool ASSP.

Am I missing something? 

Best,
Chris

Eric B. wrote:
> "Micheal Espinola Jr" <[EMAIL PROTECTED]> wrote in message 
> news:[EMAIL PROTECTED]
>   
>> Charles Marcus wrote:
>>     
>>> I've never used it either, and would not do so, since it is supposedly a
>>> security risk (not sure on the whys and hows).
>>>       
>> Most likely because it could be tricked by IP spoofing known clients.
>>     
>
> Also because your MTA will allow any client from the same IP to connect for 
> a period of time after the IP has checked a POP account.  So, if your PC is 
> behind a NAT and checking a public POP machine, any PC behind your NAT box 
> will have access to relaying email through the SMTP for a fixed amount of 
> time (sometimes 5 mins, sometimes 45mins).
>
> Eric 
>
>
>
>
> -------------------------------------------------------------------------
> Take Surveys. Earn Cash. Influence the Future of IT
> Join SourceForge.net's Techsay panel and you'll get the chance to share your
> opinions on IT & business topics through brief surveys - and earn cash
> http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV
> _______________________________________________
> Assp-user mailing list
> Assp-user@lists.sourceforge.net
> https://lists.sourceforge.net/lists/listinfo/assp-user
>
>   


-------------------------------------------------------------------------
Take Surveys. Earn Cash. Influence the Future of IT
Join SourceForge.net's Techsay panel and you'll get the chance to share your
opinions on IT & business topics through brief surveys - and earn cash
http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV
_______________________________________________
Assp-user mailing list
Assp-user@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/assp-user

Reply via email to