Re: [Exim] [ Exim 3.36 ] SMTP AUTH hacked ?

Page principale
Supprimer ce message
Répondre à ce message
Auteur: Georges Arnould
Date:  
À: exim-users, Nico Erfurth
Sujet: Re: [Exim] [ Exim 3.36 ] SMTP AUTH hacked ?
> I agree with Nico; that lookup of yours will end up as an empty string
> if the lookup fails. So all the spammers have to do is supply an empty
> string as a password for a non-existant user. At least, that's what
> appears to be the case.


Well, I thought about immediately suiciding myself, but you wouldn't have
had this message. I just tested to send a message auth'ing with an empty
password and my Fort Knox Mailer relayed the message as it was as precious
as a love letter. I used the famous french "Ligne Maginot" strategy ...

- "And then, we heard a gun shooting, Mr Policeman !"

_Many_ thanks !

Georges