PEAR Return-Path

217 Views Asked by At

Using PHP (5.2.17) and PEAR (CVS: $Id: Mail.php 294747 2010-02-08 08:18:33Z clockwerx $) to test Return-Path functionality. Reason: Client getting flooded with 'failure notice' messages for messages they didn't send.

My findings: Anyone using PEAR can insert any email id into the Header Return-Path with all failure notices routed to that path without restrictions! It would appear someone could flood an account with failure notices simply by spawning a series of messages which 1) are targeted towards non-existing email ids, and 2) have the "Return-Path" set to their unfortunate target.

Am I, hopefully, missing something?

0

There are 0 best solutions below