Topic: Identity forging using roundcube
Hi,
I find that one is able to create an alternate identity using roundcube. This is done without any verification and allows a user to send a mail using any email address. For instance if the valid mailserver user is mjackson@bad.com, he can add an identity stating bill.gates@microsoft.com and send an email using the same.
The issue I think is on the mailserver side, that should not accept mails from any other user other than mjackson@bad.com. Is there some configuration somewhere where we could limit or restrict this.
I am using the lates iredmail server.
Thanks in anticipation.
Regards,
Shomiron
----
Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.