Jonathan Schleifer wrote:
> For c.):
> 
> It seems that every client happily answers to IQ requests when they are
> sent from a JID only containing a host, e.g. <iq from='attacker.com'
> type='get'> will always be answered.

So file bug reports with those client teams. The same goes for the other
points you bring up.

Peter

-- 
Peter Saint-Andre
https://stpeter.im/

Reply via email to