[imp] foreign mailservers work even though i don't let user to type in a mailserver?

Phillip Stevens pj2k@hotmail.com
Mon, 01 Apr 2002 19:31:00 +1000


>
>In conf.php in IMP: for the question "If we are not using the server list,
>should we allow users to type in a mail server?"...
>
>I first chose "true" and the login.php page would request for a username,
>password, mailserver and port. I saved this page locally to my PC. I then
>altered conf.php and select "false" to the question. The login.php would
>then only request for a username and password (which is correct). However,
>if I attempt to login using the page that I saved locally, it allows me to
>enter foreign mailservers and actually login? (and ultimately send emails)


Should I hardcode the domain into the login script? I'm not sure what I have 
missed, because as it currently stands anyone could pass the extra form 
information to my installation of imp and login (and send emails!)


Thank you.

_________________________________________________________________
Chat with friends online, try MSN Messenger: http://messenger.msn.com