RE: Using SMTP Engine from outside the network

  • From: "MJ" <mjtech@xxxxxxxxx>
  • To: "[ExchangeList]" <exchangelist@xxxxxxxxxxxxx>
  • Date: Sun, 15 Jan 2006 21:38:41 -0500

the SMTP Relay is locked down to specific IP Addresses, but my situation is
that I was able to use a valid email addresses witin the organization from
outside the firewall without having to provide a user name and a password.

Thanks

-----Original Message-----
From: Carl Houseman [mailto:c.houseman@xxxxxxxxx]
Sent: Sunday, January 15, 2006 9:34 PM
To: [ExchangeList]
Subject: [exchangelist] RE: Using SMTP Engine from outside the network


http://www.MSExchange.org/

It may or may not be "normal" (i.e. "default") depending on your version of
Exchange.  The feature you have left enabled (Exchange 5.5) or accidentally
enabled (Exchange 200x) is called "relay".

Information on turning it off:
http://www.google.com/search?hl=en&q=exchange+relay

If the above isn't sufficient, then identify your version of Exchange for
more specific instruction.

You might also check to see if your mail system's outside IP address has
been blacklisted.  If so, it means your mail system has been used for
sending spam.
http://www.dnsstuff.com/  Use "Spam database lookup"

Even permitting relay just to authorized users is hazardous and can leave
your mail system open to abuse from unauthorized parties, unless you ensure
that authorized relayers have very strong passwords.

-----Original Message-----
From: Bryan [mailto:mjtech@xxxxxxxxx]
Sent: Sunday, January 15, 2006 9:10 PM
To: [ExchangeList]
Subject: [exchangelist] Using SMTP Engine from outside the network

Hi all,

I was working on a batch file to make it run ipconfig /all create a text
file with the result and email it to me.
While working on it I discovered that I was able to use our SMTP engine
from outside without any authentication, like this:

commail.exe -host=ServerName.DomainName.com -from=MyEmail1@xxxxxxxxxxxxxxx
-to=MyEmail2@xxxxxxxxxxxxxxx

Is this normal?

How can I secure it so it would only be used by authorized personels.

Thanks


------------------------------------------------------
List Archives: http://www.webelists.com/cgi/lyris.pl?enter=exchangelist
Exchange Newsletters: http://www.msexchange.org/pages/newsletter.asp
------------------------------------------------------
Visit TechGenix.com for more information about our other sites:
http://www.techgenix.com
------------------------------------------------------
You are currently subscribed to this MSExchange.org Discussion List as:
mjtech@xxxxxxxxx
To unsubscribe visit
http://www.webelists.com/cgi/lyris.pl?enter=exchangelist
Report abuse to info@xxxxxxxxxxxxxx



Other related posts: