RE: Pop3 allows sending messages with clear password (help!)

  • From: "William T. Holmes" <wtholmes@xxxxxxxxxxxxxx>
  • To: "[ExchangeList]" <exchangelist@xxxxxxxxxxxxx>
  • Date: Wed, 16 Apr 2003 01:22:12 -0400

Hello,

Do you have the allow relay for authenticated hosts checked? Do you have you 
client set to authenticate the SMTP connection? The answers to both of these 
questions must be yes if you wish to have the pop clients send mail.

Bill

-----Original Message-----
From: Filipa Maria Pacheco Gaudencio [mailto:fgaudencio@xxxxxx] 
Sent: Tuesday, April 15, 2003 12:55 PM
To: [ExchangeList]
Subject: [exchangelist] RE: Pop3 allows sending messages with clear password 
(help!)


http://www.MSExchange.org/

Hello again,

First of all thank you for answering.
When I said Pop3, I was referring to Pop/SMTP connections.

But my problem is this, on my Default SMTP Virtual Server I only allow relay to 
a single computer, a Lotus server.

On authentication I have the three options selected (Allow Anonymous, Basic 
Authentication, Windows Security Package). And if I remove the Anonymous, my 
pop3/smtp clients aren't able to send messages.

Is there a document, that clarifies the correct configuration of a SMTP Virtual 
Server, or have you got any other sugestion?

Tank you,

__________________________________________________
Filipa Maria Pacheco Gaudêncio

-----Original Message-----
From: William Holmes [mailto:wtholmes@xxxxxxxxxxxxxx] 
Sent: segunda-feira, 14 de Abril de 2003 20:01
To: [ExchangeList]
Subject: [exchangelist] RE: Pop3 allows sending messages with clear password 
(help!)

http://www.MSExchange.org/

Hello,

POP only receives mail, it does not send mail. SMTP is used to send mail. If 
you have chosen an SMTP server that has no restrictions on sending then anyone 
can send. If you have relaying on your SMTP server disabled then the users of 
the SMTP server will only be able to send to local accounts.

If you would like to prevent users from sending then you need to set 
appropriate restrictions on the SMTP virtual server that users have available 
to them.

Bill

-----Original Message-----
From: Filipa Maria Pacheco Gaudencio [mailto:fgaudencio@xxxxxx] 
Sent: Monday, April 14, 2003 1:16 PM
To: [ExchangeList]
Subject: [exchangelist] Pop3 allows sending messages with clear password (help!)
Importance: High

http://www.MSExchange.org/

Hi everybody,
I would like to ask you two questions,
        1- are your Pop3 clients able to send messages using any account of the 
domain, if they don't use the password?
        2 - how can I prevent this from happening?

If I configure a Pop3 account on OExpress, and use any account in the account 
name without password, I can send messages to everybody inside the domain.

For example, my e-mail address is fgaudencio@xxxxxxx if I configure my pop3 
connection to use the account name fgaudencio and the password is clear, I'm 
able to send messages to everybody inside the ipg.pt.

Can you help me?

__________________________________________________
Filipa Maria Pacheco Gaudêncio


------------------------------------------------------
List Archives: http://www.webelists.com/cgi/lyris.pl?enter=exchangelist
Exchange Newsletters: http://www.msexchange.org/pages/newsletter.asp
Exchange FAQ: http://www.msexchange.org/pages/larticle.asp?type=FAQ
------------------------------------------------------
ISA Server Resource Site: http://www.isaserver.org
Windows Security Resource Site: http://www.windowsecurity.com/ Windows 2000/NT 
Fax Solutions: http://www.ntfaxfaq.com
------------------------------------------------------
You are currently subscribed to this MSExchange.org Discussion List as: 
wtholmes@xxxxxxxxxxxxxx To unsubscribe send a blank email to 
$subst('Email.Unsub')

------------------------------------------------------
List Archives: http://www.webelists.com/cgi/lyris.pl?enter=exchangelist
Exchange Newsletters: http://www.msexchange.org/pages/newsletter.asp
Exchange FAQ: http://www.msexchange.org/pages/larticle.asp?type=FAQ
------------------------------------------------------
ISA Server Resource Site: http://www.isaserver.org
Windows Security Resource Site: http://www.windowsecurity.com/ Windows 2000/NT 
Fax Solutions: http://www.ntfaxfaq.com
------------------------------------------------------
You are currently subscribed to this MSExchange.org Discussion List as: 
fgaudencio@xxxxxx To unsubscribe send a blank email to $subst('Email.Unsub')

------------------------------------------------------
List Archives: http://www.webelists.com/cgi/lyris.pl?enter=exchangelist
Exchange Newsletters: http://www.msexchange.org/pages/newsletter.asp
Exchange FAQ: http://www.msexchange.org/pages/larticle.asp?type=FAQ
------------------------------------------------------
ISA Server Resource Site: http://www.isaserver.org
Windows Security Resource Site: http://www.windowsecurity.com/ Windows 2000/NT 
Fax Solutions: http://www.ntfaxfaq.com
------------------------------------------------------
You are currently subscribed to this MSExchange.org Discussion List as: 
wtholmes@xxxxxxxxxxxxxx To unsubscribe send a blank email to 
$subst('Email.Unsub')


Other related posts: