I have Imail server with many domains run on it....
Now a days my one of my clients

He's on one your ip's and you run "relay for addresses" ?


He's not on one your "relay for addresses" but you are running "relay for local users or domains"?

 told me that he realized that if someone
creates an Identity with non-exist email account on Outlook express then
configured the SMTP server as SMTP.MYDOMAIN.COM then he can send Emails
through my SMTPserver even his account does not exist on the mail server....
He can send emails to the entire domain

if you run a nobody alias, he, from any ip, can send mail to [EMAIL PROTECTED], and be fooled into thinking hes is sending to all existing accounts.


You can only send mail to existing accounts if you use the real address. else, the mails goes into the nobody spam-eater (and "dumb cracker" ) account.

and to outsiders domaind...

"relay for addresses" again


Please how can we prevent such user from using my Imail server as SMTP
server unless I created him a real email account on my server????

"no relay" or "relay of addresses" for an extremely limited number of ip's.


Follow your clients instructions and repeat the "crack" and then let us know.

Len


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to