Bug#478716: Too easy to create an open SMTP relay?

Andreas Metzler ametzler at downhill.at.eu.org
Thu May 1 08:37:30 UTC 2008


On 2008-04-30 Daniel James <daniel at 64studio.com> wrote:
> Package: exim4-config
> Version: 4.63-17
> Severity: normal

> When running dpkg-reconfigure exim4-config on an Etch server I noticed 
> that selecting the type of mailserver as 'smarthost' but then leaving 
> the field for the address of the smarthost blank turned the server into 
> an open SMTP relay. Would appreciate it if someone could try to 
> reproduce this.

I have tried and failed. :-(

The usual ACLs seemed to work for me:
>>> processing "require"
>>> check domains = +local_domains : +relay_to_domains
>>> gmx.net in ""? no (end of list)
>>> gmx.net in "+local_domains : +relay_to_domains"? no (end of list)
>>> require: condition test failed
550 relay not permitted


cu andreas

-- 
`What a good friend you are to him, Dr. Maturin. His other friends are
so grateful to you.'
`I sew his ears on from time to time, sure'





More information about the Pkg-exim4-maintainers mailing list