OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
smtp auth question

From: Omer Faruk Sen (omerfaruk.net)
Date: Wed Jun 02 2004 - 01:17:49 CDT


Hi,

I have realised on my mail server that when users are authenticated
against my smtp server they can change From: field with different username
within my domain. MS outlook express allows you to specify different
SMTP-AUTH username/pass than your account. Thus a clever!! user can abuse
it with authenticating against my smtp server but can send mails under
another account. Is there a way to prevent this?

REGARDS

--
Omer Faruk Sen
http://www.faruk.net
Public Key: http://www.faruk.net/omer.asc