I have Imail server with many domains run on it.... Now a days my one of my clients
He's on one your ip's and you run "relay for addresses" ?
He's not on one your "relay for addresses" but you are running "relay for local users or domains"?
told me that he realized that if someone creates an Identity with non-exist email account on Outlook express then configured the SMTP server as SMTP.MYDOMAIN.COM then he can send Emails through my SMTPserver even his account does not exist on the mail server.... He can send emails to the entire domain
if you run a nobody alias, he, from any ip, can send mail to [EMAIL PROTECTED], and be fooled into thinking hes is sending to all existing accounts.
You can only send mail to existing accounts if you use the real address. else, the mails goes into the nobody spam-eater (and "dumb cracker" ) account.
and to outsiders domaind...
"relay for addresses" again
Please how can we prevent such user from using my Imail server as SMTP server unless I created him a real email account on my server????
"no relay" or "relay of addresses" for an extremely limited number of ip's.
Follow your clients instructions and repeat the "crack" and then let us know.
Len
To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
