XMailforum is a readonly knowledge archive now.

Registering as a new user or answering posts is not possible anymore.

Might the force be with you, to find here what you are looking for.

2019-09-20 - hschneider, Admin

Cookie Disclaimer: This forum uses only essential, anonymous session cookies (xmailforum*), nothing to be scared of.

XMail Forum [Powered by Invision Power Board]
Printable Version of Topic
Click here to view this topic in its original format
XMail Forum > XMail Server > Auth Problem, Can Send Without Password


Posted by: Fago Dec 13 2011, 04:16 PM
I've noticed that someone from the outside can log into my server and send e-mail to my xmail users without any password.

Check that:
CODE
telnet mail.mydomain.pl 25


M: Me
S: Server

CODE

S: 220 ESMTP mail.mydomain.pl
M: HELO anotherdomain.pl
S: 250 mail.mydomain.pl
M: MAIL FROM:<me@anotherdomain.pl>
S: 250 Ok
M: RCPT TO:<user@mydomain.pl>
S: 250 Ok


Settings:
EnableAuthSMTP-POP3 is set to "0"
smtprelay.tab is empty
#"SmtpConfig"[TAB]"mail-auth" is commented

Domains.tab:
mail.mydomain.pl

I saw that someone here had same problem:
http://old.nabble.com/xmail-serious-auth-problem-td25985348.html

Its possible to fix that?

Posted by: Sob Dec 25 2011, 12:44 AM
It's not bug, it's feature. There's difference between accepting mail for domains owned by server and relaying mail elsewhere. Open relay is bad thing. But accepting mail for own domains from anyone is how the whole mail system works. Other servers have no way to know any password for your server. So "fixing" this would mean no incoming mail for your users from other servers. And people usually do want to receive mail from other servers/domains. wink.gif

But if you know what you're doing, XMail can filter incoming messages. The keyword to look for in manual is filters.in.tab.

Powered by Invision Power Board (http://www.invisionboard.com)
© Invision Power Services (http://www.invisionpower.com)