Re: [Exim] [ Exim 3.36 ] SMTP AUTH hacked ?

Top Page
Delete this message
Reply to this message
Author: Nico Erfurth
Date:  
To: Georges Arnould
CC: exim-users, Philip Hazel
Subject: Re: [Exim] [ Exim 3.36 ] SMTP AUTH hacked ?
Georges Arnould wrote:
>>I agree with Nico; that lookup of yours will end up as an empty string
>>if the lookup fails. So all the spammers have to do is supply an empty
>>string as a password for a non-existant user. At least, that's what
>>appears to be the case.
>
>
> Well, I thought about immediately suiciding myself, but you wouldn't have
> had this message. I just tested to send a message auth'ing with an empty
> password and my Fort Knox Mailer relayed the message as it was as precious
> as a love letter. I used the famous french "Ligne Maginot" strategy ...


You are not the first one ;)

Philip, maybe this should be in the docs, BIG AND FAT!
Somewhere in spec.txt related to the authenticators.

Nico