I think your program's fine. I don't think the other tests with openssl
really showed the bug. I think this does.
Now, can you run your program against port 587 as well as 25?
P.S. Spamdyke Sam replied to my post. While he doesn't think this is
necessarily a vulnerability (and I tend to agree with him), it does
appear to be an RFC violation, and he'll looking into fixing spamdyke.
--
-Eric 'shubes'
On 03/08/2011 01:50 PM, Eric Broch wrote:
I wrote a 'C++' program to test this issue but the output was different
than it was when testing with the openssl package. I'm not sure what
would be wrong with my program, if anything (I'm open to suggestions).
Anyway, here's the output from my 'C++' program for both scenarios and
the program below.
Build/Run
g++ -o test text.cpp
./test (server ip) (port)
STARTTLS
220 poweredgeT105.whitehorsetc.com - Welcome to Qmail Toaster Ver. 1.3
SMTP Server ESMTP
ehlo
250-poweredgeT105.whitehorsetc.com - Welcome to Qmail Toaster Ver. 1.3
SMTP Server
250-STARTTLS
250-PIPELINING
250-8BITMIME
250-SIZE 20971520
250 AUTH LOGIN PLAIN CRAM-MD5
STARTTLS
220 Proceed.
STARTTLS/RSET
220 poweredgeT105.whitehorsetc.com - Welcome to Qmail Toaster Ver. 1.3
SMTP Server ESMTP
ehlo
250-poweredgeT105.whitehorsetc.com - Welcome to Qmail Toaster Ver. 1.3
SMTP Server
250-STARTTLS
250-PIPELINING
250-8BITMIME
250-SIZE 20971520
250 AUTH LOGIN PLAIN CRAM-MD5
STARTTLS
RSET
220 Proceed.
---------------------------------------------------------------------------------
Qmailtoaster is sponsored by Vickers Consulting Group
(www.vickersconsulting.com)
Vickers Consulting Group offers Qmailtoaster support and installations.
If you need professional help with your setup, contact them today!
---------------------------------------------------------------------------------
Please visit qmailtoaster.com for the latest news, updates, and packages.
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]