Groups | Blog | Home
all groups > iis smtp nntp > august 2005 >

iis smtp nntp : setting up SMTP on 2003 server


nudge
8/3/2005 3:05:05 AM
hi,

we have a website directory for people to contact the advertisers and we are
using smtp and ASP.

there are only 2 pop3's established, each of which are for our company's
normal internal use.

so a normal web user sees a company advertised on our website and wishes to
contact him - he completes a normal form, and sends an email to the company
and to us as CC.

the server has the following smtp settings. we have a german server, so i
hope i have translated these correctly.

1 single IP address on port 25.
access -> authentication - anonymous
access -> connection control -> everyone EXCEPT a small list of known urls
that have already attacked our system
access -> relaying -> everyone EXCEPT a small list of known urls that have
already attacked our system
relaying -> outgoing security -> anonymous
relaying -> extended -> our domainname and as our server does not have it's
own dns we are using the smarthost of our provider.
both checkboxes under the smarthost field are NOT checked.
LDAP -> nothing changed - all left unchecked.
security -> administrators, network and local services

so my question is how can we stop relay attacks, whilst ensuring a normal
websuser can still send an email to 1 or multiple advertisers from our site?

jeff.nospam NO[at]SPAM zina.com
8/4/2005 12:00:00 AM
On Wed, 3 Aug 2005 03:05:05 -0700, "nudge"
[quoted text, click to view]

Assuming you didn't allow relays, then you're not relaying. Server
2003 has relays off by default. A better option is to close SMTP
incoming in your firewall, if all you do is send out from this system.

nudge
8/5/2005 1:08:02 AM
hi jeff, and thanks for your reply.

i have done some checks and it looks like we are in fact an "open relay".
despite this server going live about 2 months ago, we also seem to be listed
on the ORDB.

due to the nature of our business, we need website users to send emails to
our advertisers - therefore i think we need an open relay. i can't see how i
can use authentication.

do you have any ides about how to make our system more secure?

many thanks




i have tried

[quoted text, click to view]
jeff.nospam NO[at]SPAM zina.com
8/6/2005 4:18:36 PM
On Fri, 5 Aug 2005 01:08:02 -0700, "nudge"
[quoted text, click to view]

You don't need an open relay. You need to allow relaying for your web
server, probably by IP address, but no one else.

[quoted text, click to view]

Have you looked at using a firewall?

Jeff



[quoted text, click to view]
Peter D. Hipson
8/10/2005 6:08:21 PM
The settings you listed in your previous message will allow relaying:

[quoted text, click to view]

This should be set to noone except for a list of allowed sites.

On Fri, 5 Aug 2005 01:08:02 -0700, "nudge"
[quoted text, click to view]

PeterD, the Darkstar Network
To email, fix my address!
AddThis Social Bookmark Button