[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] mailrouting problem -> problem solved



Jeff posted:
> MAIL FROM: <jlasman@xxxxxxxxxxxxx>

You know, i'm glad you posted that, tho i'm a bit depressed....
Since it's been a while since i had a one on one with a smtp server i
thought i'd see how paranoid my raq2 is....

220 admin.growminds.com ESMTP Sendmail 8.9.3/8.9.3; Sun, 14 May 2000...

EHLO localhost

250-admin.growminds.com Hello root@xxxxxxxxxxxxxxxxxxxxxxx
[155.212.71.87], pleased to meet you

You're me? no problem.....*doh*

MAIL FROM: gsh@xxxxxxxxxxxxx
250 gsh@xxxxxxxxxxxxxxxx Sender ok

Sender ok...Since when? It's an internal username

RCPT TO: gsh@xxxxxxxxxxxxx
250 gsh@xxxxxxxxxxxxxxxx Recipient ok

Want to send in a circle? Sure, no problem.....

Really sad part, in addition to being more than happy about forging an
email, it picked up me Gecos info and inserted my name into the mail,
making it look perfectly legit (provided you don't look to closely at the
headers, but most users never do)

*Sigh*

Think i need to go find my sendmail boog again, i kinda sssumed the raq's
default config was tighter than this...foo on me..

gsh