Results 1 to 5 of 5

Thread: Persona spoofing

  1. #1
    skyflyer is offline Active Member
    Join Date
    Mar 2011
    Posts
    39
    Rep Power
    4

    Exclamation Persona spoofing

    Hi!

    From what I've experienced during my tests today, Zimbra's persona feature lets a user spoof an existing email address on the Zimbra server, which is... very unfortunate. Of course, this works as long as the user or COS has the setting "Allow sending email from any address".

    I could enter an email address of a already existing user in Zimbra and successfully send a mail out of Zimbra. Is this really by design? And it seems that this setting is ON by default?

    Additionaly, I've found out that replying to a mail sent by my persona (say xyz@domain.com) fails with recipient address rejected message.

    On a side note: is there a setting which allows an end user to create an email alias or are ZmSoap, zmprov or Admin gui the only ways to go about it?

    Thanks,
    Miha.
    --
    Zimbra 7.1.2 GA NETWORK

  2. #2
    phoenix is online now Zimbra Consultant & Moderator
    Join Date
    Sep 2005
    Location
    Vannes, France
    Posts
    23,473
    Rep Power
    56

    Default

    Quote Originally Posted by skyflyer View Post
    From what I've experienced during my tests today, Zimbra's persona feature lets a user spoof an existing email address on the Zimbra server, which is... very unfortunate. Of course, this works as long as the user or COS has the setting "Allow sending email from any address".
    If you don't like the feature then disable it.
    Regards


    Bill


    Acompli: A new adventure for Co-Founder KevinH.

  3. #3
    skyflyer is offline Active Member
    Join Date
    Mar 2011
    Posts
    39
    Rep Power
    4

    Default

    Hi phoenix!

    Indeed, it just seems weird why would Zimbra allow personas which already exist.

    Anyhow, I'm more interested in the "aliases" feature of it. Is there a way to allow end users to provision their own aliases through ZWC?

    Regards,
    Miha.
    --
    Zimbra 7.1.2 GA NETWORK

  4. #4
    Krishopper is offline Dedicated Member
    Join Date
    Dec 2006
    Location
    Minneapolis MN
    Posts
    777
    Rep Power
    9

    Default

    For the same reason you can set up any email client (Thunderbird, Outlook, etc) to send from any email address you want. It has the same features as a full email client.

    You can put in an RFE to ask for a feature so that users have to validate/confirm their email addresses before they can add them to a persona (like Gmail requires you to do), but there isn't currently a mechanism to do that.
    01 Networks, LLC / Cybernetik.net
    Zimbra NE and OSS Cloud Hosting
    Shared Web Hosting
    Consulting Services

  5. #5
    skyflyer is offline Active Member
    Join Date
    Mar 2011
    Posts
    39
    Rep Power
    4

    Default

    Thanks. I'll do that.

    Regards,
    Miha.
    --
    Zimbra 7.1.2 GA NETWORK

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Problems sending from a Persona
    By jbuell in forum Administrators
    Replies: 1
    Last Post: 09-12-2012, 12:05 AM
  2. Chaning account type (Primary <=> Persona)
    By Najtssob in forum Administrators
    Replies: 2
    Last Post: 04-05-2011, 12:51 AM
  3. Outlook persona - sending fails
    By jkoyle in forum Zimbra Connector for Outlook
    Replies: 7
    Last Post: 08-06-2008, 09:26 AM
  4. zimbra5 - sending from another persona in Outlook - how?
    By ryanp in forum Zimbra Connector for Outlook
    Replies: 2
    Last Post: 03-03-2008, 04:57 PM
  5. [SOLVED] Add Persona not in mail the mail server
    By Insanity5902 in forum Users
    Replies: 2
    Last Post: 01-05-2008, 10:16 PM

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •