Re: smtp_pass: why is it unneeded?
- To: mutt-users@xxxxxxxx
- Subject: Re: smtp_pass: why is it unneeded?
- From: Kyle Wheeler <kyle-mutt@xxxxxxxxxxxxxx>
- Date: Fri, 27 Jun 2008 12:47:42 -0500
- Comment: DomainKeys? See http://domainkeys.sourceforge.net/
- Dkim-signature: v=1; a=rsa-sha1; c=relaxed; d=memoryhole.net; h=date :from:to:subject:message-id:references:mime-version:content-type :in-reply-to; s=default; bh=7n6ADHhIZAqI+821Q97LtNE23gg=; b=S9rE xW2bcDF9gz3AqlgMTDoj9nBjIkt4+ty0mDw0RfThlPi6kaMEOrJvxXZBvCB0e8Pq 6C0faDnPIM6Bz+zvsDOYHvWV0dUH9cRrGXmDIpg0uDSO8LR+Ggj2whO34BarC4qk 7lDND+xYgWG+d4AydsYyr3UA68KlJnP+Bta4hkY=
- Domainkey-signature: a=rsa-sha1; q=dns; c=nofws; s=default; d=memoryhole.net; b=b7/ZqfFw4wR/xtQKjMCuBl00caW5s9laIgG8MdFHj7rd/5TS1iC8BpsNxQpK3Id3SKc7Yz+JD0OC4EqplJAKUut107kkZ2UYfgnpP4q8Yi2sBsGLCHlB55t8grNksyR+dYrVYRNwi4llVH0YXdMRU/a1wX98hgtAkD/JQEioZk0=; h=Received:Received:Date:From:To:Subject:Message-ID:Mail-Followup-To:References:MIME-Version:Content-Type:Content-Disposition:In-Reply-To:OpenPGP:User-Agent;
- In-reply-to: <20080625174234.GO7064@xxxxxxxxxx>
- List-post: <mailto:mutt-users@mutt.org>
- List-unsubscribe: send mail to majordomo@mutt.org, body only "unsubscribe mutt-users"
- Mail-followup-to: mutt-users@xxxxxxxx
- Openpgp: id=CA8E235E; url=http://www.memoryhole.net/~kyle/kyle-pgp.asc; preference=signencrypt
- References: <20080624133016.GA598@xxxxxxxxxxxx> <20080624153112.GA90179@xxxxxxxxxxxxx> <20080625174234.GO7064@xxxxxxxxxx>
- Sender: owner-mutt-users@xxxxxxxx
- User-agent: Mutt/1.5.18 (2008-06-25)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
On Wednesday, June 25 at 07:42 PM, quoth Michelle Konzack:
> Am 2008-06-24 10:31:12, schrieb Kyle Wheeler:
>> Unlikely. More likely, your server has implemented IMAP-before-SMTP,
>> which means anyone from your IP address can send email via SMTP
>> without a username or password. It's not that it's figuring out what
>> your username and password are, it's that successful logins to your
>> IMAP server probably put your IP address on a whitelist that your SMTP
>> server uses.
>
> Does this work only with Linux Clients or under Windows too?
If your server uses this technique, it doesn't matter what OS or
software the client is using.
> Hmmm, there are inteligent Viriis and Trojans which use the SMTP
> relay of ones provider... and if he/she connect successfuly to
> IMAP, the Viriis or Trojans can spam the world "legaly"...
Indeed. But then, if they can authenticate to your ISP via IMAP,
there's little reason to think that they can't also authenticate to
your ISP via SMTP (it's usually the same username and password, and
the same server even).
>> for each is absolutely necessary, I just implemented
>> IMAP-before-SMTP. The devil is in the details, and there are some
>> drawbacks to this kind of policy (which I can get into, but is
>> probably offtopic of this list), but it's a common-enough setup
>> that I wouldn't be surprised if your server does it.
>
> The thing above?
... I'm afraid I don't understand what you're asking. As a guess...
yes, the "it" in the phrase "if your server does it" is referring to
IMAP-before-SMTP.
~Kyle
- --
Idealism increases in direct proportion to one's distance from the
problem.
-- John Galsworthy
-----BEGIN PGP SIGNATURE-----
Comment: Thank you for using encryption!
iEYEARECAAYFAkhlJ74ACgkQBkIOoMqOI16MgACcDCUY/4zu0jB18FFnaLCCKu15
NfwAoOxlP20zxrigogXqieFfkjcODkyT
=XQLD
-----END PGP SIGNATURE-----