Autor: Chad Leigh -- Shire.Net LLC Data: A: Exim User's Mailing List Assumpte: [exim] harvesting email addresses from an exim server?
Hi
Can spammers somehow query an exim server to try and determine email
addresses (besides a brute force of trying to send to a random list)?
We have an exim server that is totally virtual (ie, no unix usernames
receive email through it) using a custom ldap config.
(At least) one of the accounts served by this server has started
receiving spam. But the account was used only internally and never in
public for spammers to harvest, so the big boss is wondering if somehow
the server could be made to give up its secrets and reveal valid
recipients somehow other than through somesort of brute force passing
in millions of possibilities (which has not happened according to our
logs).