creating user-mailboxes without cyradm

Rob Siemborski rjs3 at andrew.cmu.edu
Wed Feb 5 14:13:55 EST 2003


On Wed, 5 Feb 2003, Hans Wilmer wrote:

> How is this dealt with in respect to security and reliability?

Only admins can do this for any username, there is a config option that
allows authenticated users to do this for their own mailbox, but no
others.

> Just write a script that logs in and automatically creates mailboxes
> from randomly generated (user-) names until the storage is
> full. That's sort of making DOS attacks utterly easy.

If your admins are trying to DOS you, you've got bigger problems.

-Rob

-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 207 * 412-268-7456
Research Systems Programmer * /usr/contributed Gatekeeper





More information about the Info-cyrus mailing list