Autor: Nico Erfurth Datum: To: Georges Arnould CC: exim-users, Philip Hazel Betreff: Re: [Exim] [ Exim 3.36 ] SMTP AUTH hacked ?
Georges Arnould wrote: >>I agree with Nico; that lookup of yours will end up as an empty string
>>if the lookup fails. So all the spammers have to do is supply an empty
>>string as a password for a non-existant user. At least, that's what
>>appears to be the case.
>
>
> Well, I thought about immediately suiciding myself, but you wouldn't have
> had this message. I just tested to send a message auth'ing with an empty
> password and my Fort Knox Mailer relayed the message as it was as precious
> as a love letter. I used the famous french "Ligne Maginot" strategy ...
You are not the first one ;)
Philip, maybe this should be in the docs, BIG AND FAT!
Somewhere in spec.txt related to the authenticators.