Security Basics mailing list archives

Re: Re: Sender Spoofing via SMTP


From: "Bryan S. Sampsel" <bsampsel () libertyactivist org>
Date: Mon, 7 Nov 2005 15:57:33 -0700 (MST)

Additionally, you could set up a grey-list configuration.

http://www.greylisting.org/

I'm not sure about Exchange, but I'd put a unix/linux relay in front of
the exchange server anyways for SMTP traffic.  But that's my opinion and
may not fly with his environment.

Telnet connections to the SMTP port can happen, it's a matter of how his
server reacts to what is entered.  Grey listing might help cut down on
that risk...but only against outside entities.  If he's trying to secure
it internally, he's going to have to look into the specifics of MS
Exchange.

Mileage may vary.

Sincerely,

Bryan S. Sampsel
LibertyActivist.org


dominiquesb () collegeestrie com wrote:
Why don't you block connection from your internal range of address and use
RBL (Real-Time Blacklist) to filter connection from the internet?

Good Luck

Dom



Current thread: