any idea on this one ?
the issue is ... anyone can use any email address and send mail using
linux system user. It cant be a bug.. i think I am missing something.
I just dont get which one!


--- In [email protected], "DoOrsOfpErcEpTioN"
<[EMAIL PROTECTED]> wrote:
>
> Hi,
> 
> I have a sendmail setup with linux system users as the login
> 
> --> [EMAIL PROTECTED] here the username is 'user1'
> --> The mail server works for single domain.
> 
> Now, I am faced with an issue that anyone can edit sender (from addr)
> as [EMAIL PROTECTED] (in outlook for instance)and use the
> username/passwd of user1 and send an email.
> 
> The mail actually uses sender address as [EMAIL PROTECTED] and on
> reply it will go to user2.
> 
> The issue I am facing here is that of envelope address. It doesnt
> verify if the address belong to the user. How do I configure sendmail
> to check it? I have gone through 'Local_check_mail' CF command as
> mentioned here--> http://sendmail.cuzuco.com/ , but I guess that is
> not useful. Is there any other method to get this right ?
> 
> regs,
> 
> DoOrsOfpErcEpTiON
>


Reply via email to