Tricking Anti-Relay Commands

Top Page
Delete this message
Reply to this message
Author: Jawaid Bazyar
Date:  
To: exim-users
Subject: Tricking Anti-Relay Commands

Greetings,

on the suggestion of someone on the inet-access list (a list for ISPs
where I am plugging exim heartily ;) I tried the following:

>From a host not in our accepted relay list:


telnet hypermall.com 25
MAIL FROM: bazyar@???
RCPT TO: anyone%anywhere.com@???
... is syntactically correct

I.E., munging up the address as above causes Exim to not properly reject
this message. I suspect it ought to check to see if there's a % in the
local part and go ahead and drop the "@hypermall.com" if that's possible.

With this 'hole', spammers can still relay off my mail box. :(

Comments, suggestions?

Thanks in advance,

Jawaid

--
 Jawaid Bazyar              |   Affordable WWW & Internet Solutions
 Interlink Advertising Svcs |   for Small Business
 bazyar@???       |   P.O Box 641               (303) 781-3273
 --The Future is Now!--     |   Englewood, CO 80151-0641  (303) 789-4197 fax