Current User: Guest Login Register
Please consider registering


Register? | Lost Your Password?

Search Forums:


 






Minimum search word length is 4 characters – Maximum search word length is 84 characters
Wildcard Usage:
*  matches any number of characters    %  matches exactly one character

postfix send via smtp without auth between users of a domain

Reply to Post Add a New Topic
UserPost

1:16 pm
December 24, 2009


colnpanic

New Member

posts 1

i found the Postfix SMTP Authentication and Dovecot SASL setup how-to at http://www.linuxmail.info/post…..ecot-sasl/, first off thanks for taking the time to write it and respond to everyone's questions.

the reason i was looking in the first place is that i am able to send mail via telnet (and possibly a mail client, haven't tried it…) without authenticating between any users in the postfix server.  you mention a couple times in the comments on the how-to that this is "normal" / proper behaviour, why is this ok?  for instance, i can telnet in and send mail from "boss@myorg.com" and tell everyone they are fired, or send mail to "boss@myorg.com" as any user in the system telling him he smells.  while this can be fun and all, it is not behaviour i want to leave enabled…

you (consultant) replied a couple of times to a similar scenario mentioned in the comments with "That’s the correct behavior. Otherwise, you won’t be able to accept mail from the outside."  i guess my question is what does this behaviour have to do with accepting mail from outside, isn't mail accepted based on the "@myorg.com" being in the accepted domains list regardless of what the sending domain is?  it just seems like a very bad scenario, especially if you don't know/trust your users, or anyone that knows usernames and your mail server address.

thanks again for helping everyone with their mail servers, happy holidays!

jay

8:03 pm
December 26, 2009


consultant

Admin

posts 341

Hi jay,

Yes, it is a very bad scenario. Unfortunately, there is still no solution for email spoofing. See

http://www.windowsecurity.com/…..ofing.html

Reply to Post

Reply to Topic:
postfix send via smtp without auth between users of a domain

Guest Name (Required):

Guest Email (Required):

Smileys
Confused Cool Cry Embarassed Frown Kiss Laugh Smile Surprised Wink Yell
Post New Reply

Guest URL (required)

Math Required!
What is the sum of:
10 + 11
   


About the Linux Mail Server Setup and Howto Guide Forum

Forum Timezone: America/New_York

Most Users Ever Online: 60

Currently Online:
12 Guests

Currently Browsing this Topic:
1 Guest

Forum Stats:

Groups: 2
Forums: 5
Topics: 326
Posts: 1012

Membership:

There are 928 Members
There have been 84 Guests

There is 1 Admin

Top Posters:

shanmugasundaram s – 45
Kendermin – 15
Ginger – 14
bighorn – 14
iron_michael86 – 12
Raminda – 11

Recent New Members: RaHuL, bikesh, pappy_says, geos, boudi7, dara.hr

Administrators: consultant (341 Posts)