Quote:
Originally Posted by tamarian
I think the abuse would require all the following conditions:
1. Enabling auto processing option
2. And enabling usergroupid change option
3. And allowing members to see other members email addressess (or them finding out the email addresses from the members themselves)
4. And being able to forge emails with correct bounce syntax.
But an alternative would be to ignore forged email headers. I may write some pre-checks, and/or allow the option to call user-defined scripts, like SpamAssasin and the like, to allow returning a true or false answer, and ignore emails based on that answer.
|
Good point. I dont allow users to see other users email addresses, so that should be enough to make sure its okay?