qmail smtp-auth bug allows open relay

Stephen Sprunk stephen at sprunk.org
Sat Jul 19 22:46:59 UTC 2003


Thus spake "John Brown" <jmbrown at chagresventures.com>
> seems that there are installs of the smtp-auth patch
> to qmail that accept anything as a user name and password
> and thus allow you to connect.
>
> http://marc.theaimsgroup.com/?l=qmail&m=105452174430616&w=2
>
> is one URL that talks about this.
> ...
> Some early docs on setting up qmail based smtp-auth systems
> had the config infor incorrect.  This leads to /usr/bin/true
> being used as the password checker. :(

That isn't a bug; it's a documentation problem and/or incompetent admin,
depending on how generous you're feeling.

S

Stephen Sprunk         "God does not play dice."  --Albert Einstein
CCIE #3723         "God is an inveterate gambler, and He throws the
K5SSS        dice at every possible opportunity." --Stephen Hawking




More information about the NANOG mailing list