> This is going to scribble all over your maildir, as root - not something
> you really want to happen.

I don't think you run sqwebmail as root.. it would make me cry if someone 
did...

>
> Setting this tiny glitch aside, the problem with this is that now anyone
> who knows at least one valid mail account name on this server will now be
> able to fill the account with crap.  Do it long enough, and you'll run out
> of disk space.

Well, you can have disk quotas for a user so that above an amount of 
directory space used the emails get declined.

Second, this is possible anyway. If I know your account name and I fireup an 
email client ot just use telnet I can send as many crap as I want to that 
account (not my intention to try for the record).


I think that if as admin you take the normal security precautions this patch 
is pretty save.


Of for some guarana now ;-)

Patrick Ale

Reply via email to