[imp] IMP as an open relay

Chuck Hagenbuch chuck@horde.org
Sun, 26 May 2002 22:26:44 -0400


Quoting Carlton Thomas <carlton@gifford.co.uk>:

> I think that the easiest way to combat this is to require that the
> user specify an SMTP server and SMTP authentication details when
> they specify a POP3/IMAP server which is not local (i.e. the POP3/IMAP
> server is not selected from a pull-down list). The administrator should
> be allowed to override this. however, I believe that the default should
> be to require SMTP server details where POP3/IMAP server details have
> been specified.

This is completely unworkable with most SMTP servers; a user's local SMTP 
server will likely think you're trying to relay through it if you use it 
remotely in that way.

-chuck

--
Charles Hagenbuch, <chuck@horde.org>
My intuitive grasp of mathmatics often leads me astray.