| Summary | Ability to sending email without login, spamming |
| Queue | IMP |
| Queue Version | 3.2.8 |
| Type | Bug |
| State | Not A Bug |
| Priority | 1. Low |
| Owners | |
| Requester | mezon (at) niestety (dot) pl |
| Created | 02/22/2007 (6843 days ago) |
| Due | |
| Updated | 03/09/2007 (6828 days ago) |
| Assigned | |
| Resolved | 02/22/2007 (6843 days ago) |
| Github Issue Link | |
| Github Pull Request | |
| Milestone | |
| Patch | No |
message via IMP without first being authenticated. If you don't
believe me, try directly accessing compose.php directly (without any
session information). You will get a login screen instead. If not,
your installation is seriously broken.
The only way they could use IMP to send messages is if they hijacked
the session. And exactly like Jan told you, you need to upgrade since
newer versions of Horde have further protections against this kind of
attack (i.e. IP checking).
that, you are using an ancient, unmaintained version.
using IMP as our webmail server, and we are getting
one login every minute or so, with 31 character login id's like:
20070308123837.1rzybom81m4ow8so (each login is different, but all are
31 characters long). I have had to clean out 1000's of spam messages
from the postfix system.
We are currently running Debian 1:3.3.5-13 with horde3 that came with
the install
Priority ⇒ 1. Low
State ⇒ Not A Bug
that, you are using an ancient, unmaintained version.
Priority ⇒ 3. High
Type ⇒ Bug
Summary ⇒ Ability to sending email without login, spamming
Queue ⇒ IMP
State ⇒ Unconfirmed
on my server.
It seems that they can send it by passing data via POST to proper url,
here are some entries from apache log:
POST /horde2/imp/compose.php?uniq=82628848545cdd1e23e7441171116589640
HTTP/1.1" 200 102
"https://my-server-address/horde2/imp/compose.php?popup=1&to=&cc=&bcc=&msg=&subject=&thismailbox=INBOX&uniq=1171116505671
and just after that, another one:
POST /horde2/imp/compose.php?uniq=60020459645cdd1e5ce54b1171116607218
HTTP/1.1" 200 102
"https://my-server-address/horde2/imp/compose.php?popup=1&to=&cc=&bcc=&msg=&subject=&thismailbox=INBOX&uniq=1171116508500