Re: [exim] Local user enumeration through RCPT

Página superior
Eliminar este mensaje
Responder a este mensaje
Autor: Peter Bowyer
Fecha:  
A: exim users
Asunto: Re: [exim] Local user enumeration through RCPT
On 17/12/2007, Phill Wood <phill.wood@???> wrote:
> Hi All
>
> One of the servers we look after was recently "penetration tested" and they
> could find very little wrong so they complained about silly things like it's
> possible to see which users locally exist on the server through the answer
> Exim provides to the RCPT command.


Good. Tell them to read up on email best practice.

Peter

--
Peter Bowyer
Email: peter@???