[imp] Possible bug ?

Arjen de Korte arjen+horde at de-korte.org
Sat Sep 12 12:24:57 UTC 2009


Citeren michel at casa.co.cu:

> I have recently migrated to Horde Groupware Webmail Edition 1.2.3, I
> have problems, apparently has a bug horde.
>
> Let me explain more.
>
> From abroad are using a potential vulnerability that may have horde to
> generate large amounts of mail to multiple servers, aol, hotmail, yahoo
> etc. ..

I have no idea what you're trying to say here. Could you attach the  
headers of one of these messages that you think are send through a bug  
in Horde/IMP?

> As a result brought me to block emails from my domains or IP addresses.
> when they generate this amount of advertising messages in postfix
> clearly out who was who took delivery of the mail, in this case my
> webmail. apparently everything is through compose.php page.

What makes you think this is a bug in Horde?

> I am sending you the logs generated by apache, I tried to configure   
> horde to generate logs also but I did still like it to work.
>
> But they also sent postfix logs. are not like you can generate these  
>  messages are making me look like an open relay server
>
> please do not keep quiet on the list this time, help me.

Did you also consider the possibility that someone might have  
guessed/fished a username and password? And in fact is just using a  
webmail account on your system?

Best regards, Arjen



More information about the imp mailing list