[imp] IMP as an open relay

Chuck Hagenbuch chuck@horde.org
Mon, 27 May 2002 10:06:41 -0400


Quoting Carlton Thomas <carlton@gifford.co.uk>:

> If this facility is not added, IMP installations which allow the user to 
> type in a POP3/IMAP server name *will* be abused sooner or later and will
> then be blackholed.

Installations that allow using any pop3/imap server are open to creative 
abuse anyway, and if their administrators don't take measures to restrict 
their userbase, that's their problem.

Your suggestion won't work, because the IMP demo site _can't_ send mail 
through your local ISP's SMTP server; it'll be treated as relaying and 
rejected. Unless your ISP is using SMTP auth, but that's _really_ rare.

Frankly, if someone really wants to go and abuse the IMP demo site, the 
community will just lose the demo site. It'd be sad, but it's the 
community's loss.

-chuck

--
Charles Hagenbuch, <chuck@horde.org>
My intuitive grasp of mathmatics often leads me astray.