Possible impersonation backdoor in Exim

خرید بک لینک

Lets say that one company has site with contact page where emails are shown: contact@somecompany.com, support@somecompany.com.

I have found that Exim from DA (newest, without any customization) enables u to send email from AS contact@somecompany.com TO support@somecomapany.com without authentification (mail sent from other server/IP).

Such impersonation souldnt be possible. I could send 10000 or even more mails without authentification to that user...

Example log: http://wklej.org/hash/78a2cbd5ce8/txt/

Also tested on other hosting companies servers that have DA, same problem every server.

DirectAdmin Forums...

ما را در سایت DirectAdmin Forums دنبال می‌کنید

برچسب: نویسنده: ایمان اصلاحی بازدید: 345 تاريخ: يکشنبه 1 بهمن 1396 ساعت: 7:45

صفحه بندی