any idea on this one ? the issue is ... anyone can use any email address and send mail using linux system user. It cant be a bug.. i think I am missing something. I just dont get which one!
--- In [email protected], "DoOrsOfpErcEpTioN" <[EMAIL PROTECTED]> wrote: > > Hi, > > I have a sendmail setup with linux system users as the login > > --> [EMAIL PROTECTED] here the username is 'user1' > --> The mail server works for single domain. > > Now, I am faced with an issue that anyone can edit sender (from addr) > as [EMAIL PROTECTED] (in outlook for instance)and use the > username/passwd of user1 and send an email. > > The mail actually uses sender address as [EMAIL PROTECTED] and on > reply it will go to user2. > > The issue I am facing here is that of envelope address. It doesnt > verify if the address belong to the user. How do I configure sendmail > to check it? I have gone through 'Local_check_mail' CF command as > mentioned here--> http://sendmail.cuzuco.com/ , but I guess that is > not useful. Is there any other method to get this right ? > > regs, > > DoOrsOfpErcEpTiON >
