On 2007/04/14 11:37, Paolo Supino wrote:
>   From the technical aspect, I agree with you. But non technical people 
> don't see (or understand) that :-( I wish I had time to sit down and 
> find out how to exploit the webapp.

if you don't have time to work this out, you don't have time to get
yourself off all the public and in-house blacklists. reliably getting mail
into places like aol and hotmail can be challenging at the best of times,
even without known vulnerabilities in your mail-sending setup.

> I tried to bring in a company to do penetration testing, but I was
> refused the budget for it.

you can probably just read logs/tcpdump.

