bad wakening

This was a bad morning bad wakening
I found lots of bounces in my mailbox and found out that a customer's "contact"-php-script was abused to send spam this night!

I modified the script immediately (deletet the setting of additional mail-headers that should only set "From" but were used to set BCCs.)

Is this legal to modify a customers script?

And an other question: is it possible to deny user nobody to set BCCs at all? (Postfix 2.1.x)

THx,
Michael

 

 

 

 

Top