How do I stop someone from telneting to port 25 and then creating a new email?
 
I have security set to "relay for local users" but, have tried every possible security option and it still allows jo-blow from anywhwre to login and send mail.  All he has to do is use a valid email address thats on the server (ie.  [EMAIL PROTECTED])
 
helo mydomainname.com  (any domain name works)
mail from:[EMAIL PROTECTED]  (he's now spoofed my email address)
rcpt to:[EMAIL PROTECTED] (any email address he wants)
 
at this point, all he needs to do is the data command, and he's sending email.
 
surely there is a way to keep him off the server or, a way to keep him from being able to do this??
 
-pat-
 

Reply via email to