Lets say that one company has site with contact page where emails are shown: contact@somecompany.com, support@somecompany.com.
I have found that Exim from DA (newest, without any customization) enables u to send email from AS contact@somecompany.com TO support@somecomapany.com without authentification (mail sent from other server/IP).
Such impersonation souldnt be possible. I could send 10000 or even more mails without authentification to that user...
Example log: http://wklej.org/hash/78a2cbd5ce8/txt/
Also tested on other hosting companies servers that have DA, same problem every server.
DirectAdmin Forums...
ما را در سایت DirectAdmin Forums دنبال میکنید
برچسب: نویسنده: ایمان اصلاحی بازدید: 345 تاريخ: يکشنبه 1 بهمن 1396 ساعت: 7:45