[1178] in WWW Security List Archive
Re: mail port [Off Topic]
daemon@ATHENA.MIT.EDU (Kluge)
Thu Nov 16 19:45:22 1995
Date: Thu, 16 Nov 1995 14:46:51 -0500 (EST)
From: Kluge <gfoulds@asel.udel.edu>
To: "Ross F. Jimenez" <rfjimen@tesuque.cs.sandia.gov>
cc: www-security@ns2.rutgers.edu
In-Reply-To: <Pine.SUN.3.91.951108221322.16290B-100000@tesuque.cs.sandia.gov>
Errors-To: owner-www-security@ns2.rutgers.edu
On Wed, 8 Nov 1995, Ross F. Jimenez wrote:
> I have a question... you can telnet to a mail port (25) and send mail
> from it,,to any person, and put it's from anybody you want, are you not
> suppose to do this,, or can anybody do this, can the mail be tracked ??
> It would seem like a big security flaw if you could send false mail so
> easily... ???
> Curious,
It's very easy to send 'anonymous' email via port 25. You aren't
supposed to do it, however, any user can. It is very easily trackable
however...
-Greg