[imp] IMP as an open relay

Jan Schneider jan@horde.org
Thu, 23 May 2002 10:58:18 +0200


Zitat von Christopher Audley <audley@cnsolutionsllc.com>:

> It seems to me, from scanning redirect.php and IMP.php (createSession), 
> that I can
> construct a URL to to connect any instance of IMP running on the net to 
> run against
> any IMAP server.  There is no check to limit the server specified to 
> those listed in
> servers.php.  Am I wrong about this?

Yes. The administrator can either select to use a server list, or to disable
the change of the server. In both cases the appropriate value from
servers.php will be chosen and can't be overriden by the user.

Jan.

--
http://www.horde.org - The Horde Project
http://www.ammma.de - discover your knowledge
http://www.tip4all.de - Deine private Tippgemeinschaft