Groups | Blog | Home
all groups > iis smtp nntp > october 2006 >

iis smtp nntp : Securing SMTP Relay


Ben Blackmore
10/31/2006 3:38:02 AM
Hi,

We have an SMTP relay setup on our Win 2003 server, which is also running
ISA 2004 as our corporate firewall. This relays mail to & from our backend
Exchange 2003 server.
I thought the SMTP relay was secure as I had configured it according to an
article on isaserver.org, however after running an open relay test
(http://www.rbl.jp/svcheck.php) I found that out of the 19 tests, 3 were
accepted. This has me worried, that the server could be used as an open
relay! The tests that were accepted are below, how do I secure against these
types of relay? Ar ethey actually a threat? I see the only difference on
these tests compared to the others is the 'RCPT TO:' filed, in these 3 tests,
they are all mailformed, i.e. rlytest%rep.rbl.jp, rep.rbl.jp!rlytest and
"rlytest@rep.rbl.jp" (has quotes around)

Any help, advice, suggestions much appreciated!

Relay test 7
[quoted text, click to view]
<<< 250 2.1.5 "rlytest@rep.rbl.jp"@mxsvr
relay accepted!!

Relay test 8
[quoted text, click to view]
<<< 250 2.1.5 "rlytest%rep.rbl.jp"@mxsvr
relay accepted!!

[quoted text, click to view]
<<< 250 2.1.5 rep.rbl.jp!rlytest@mxsvr
Ben Blackmore
10/31/2006 5:50:01 AM
[quoted text, click to view]

Hi Peter,

Thanks for the reply.

I'm not sure if they were actually sent or not, I'm using the relay check
found on http://www.rbl.jp/svcheck.php and the only output it shows is that
in the original post, which doesn't include whether they were sent or not. I
would 'guess' not as the email addresses wouldn't be seen as correctly
formated containing % or ! instead of an @.
I'm just double checking that the relay is secure, we have a lot of mails in
our badmail folder, that have been returned by other mail servers to non
existant users on our domain, when you open the mails the original from
address is something like uvwxyz@ourdomain.com, I know these are probably
just emails with spoofed from addresses being returned, but I wanted to
double check someone hadn't found an exploit in our relay!
I've used http://www.zoneedit.com/smtp.html which was suggested by Thomas
Shinder's article
(http://www.isaserver.org/articles/smtprelayinboundoutbound.html) which is
what I used to secure the relay. Also checked against
http://www.aupads.org/test-relay.html and a few othersall say it's secure.
Only http://www.rbl.jp/svcheck.php reported that 3 tests were accepted.

PeterD
10/31/2006 8:24:46 AM
On Tue, 31 Oct 2006 03:38:02 -0800, Ben Blackmore
[quoted text, click to view]

Before panic mode, were the emails in question actually sent, or did
SMTP just 'accept' them? The reason is that MSFT SMTP does accept some
emails that should be considered as 'bad relay' but then later just
KL
10/31/2006 6:21:45 PM


Some emails will be discarded internally, a serious relay test site will
tell you this.

Try this site, you'll have to signup to get a proper report from it:
http://www.abuse.net/relay.html

To signup you send an email to new@abuse.net and reply to it, then enter the
password on the form above.

KL.


"Ben Blackmore" <BenBlackmore@discussions.microsoft.com> skrev i meddelandet
news:C189390A-7552-4029-9448-3FBB5E3B4E91@microsoft.com...
[quoted text, click to view]

AddThis Social Bookmark Button