Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

improving smtp server security settings

Status
Not open for further replies.

intomuso

Programmer
Jan 26, 2006
19
GB
Hi,

I'm getting the following message from a network security scan (seems to be in linux terminology), does anyone know what I need to do in windows 2003 to stop this and what does it mean please?

RESULT -
"It is possible to enumerate the names of valid users on the remote host. Description : The remote SMTP server answers to the EXPN and/or VRFY commands. The EXPN command can be used to find the delivery address of mail aliases, or even the full name of the recipients, and the VRFY command may be used to check the validity of an account. Your mailer should not allow remote users to use any of these commands, because it gives them too much information."

MY SETTINGS CURRENTLY ARE

Access -> Authentification -> intergrated windows authentification

Access -> Connection -> only the list below with my server ip

Access -> Relay Restrictions -> only the list below with my ip

delivery -> outbound security -> intergrated windows security on

Thanks in advance

gavin
 
You can't enable authentication. SMTP is anonymous by nature.

Look and see if you can enable tarpitting. This will generally slow things down. There are other solutions available too, but you don't mention what email server you're actually using.

Pat Richard MVP
Plan for performance, and capacity takes care of itself. Plan for capacity, and suffer poor performance.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top