OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: smtp auth question

From: Mick Pollard (micklunix.au.com)
Date: Wed Jun 02 2004 - 01:05:38 CDT


>Thus a clever!!
> user can abuse it with authenticating against my smtp server but can
> send mails under another account. Is there a way to prevent this?
>
They will need to know the password of the account they are using to
send out with. SMTP-AUTH reuires a vaild username & password pair.
If they only know their own username & password then they can't do as
you suspected.

--
Regards
Mick Pollard ( lunix )
------------------------------------------------
BOFH Excuse of the day:
Static Registry Underflow Error