Someone will always be able to send e-mail to someone else whose e-mail account is hosted on your server, that's how e-mail works.  Anti-relay measures prevent someone from sending e-mail through your mail server to someone at a domain hosted on some other mail server.  It will never prevent mail destined for someone hosted on your mail server, unless of course you blacklist the sender's e-mail address or something.
 
Bill
----- Original Message -----
Sent: Monday, August 11, 2003 6:35 PM
Subject: Re: [IMail Forum] Telnet to port 25

i tried both "no relay"  and "relay for addresses".  In both cases i was able to telnet to port 25, then "mail from:[EMAIL PROTECTED]" and then send email to anyone at my domain.  Is this the best I can hope for?
 
Where it can be used maliciously is to telnet to the ip of someone that sent you an email, do a "helo his mail server", a "mail from" as him, and a "rcpt to" as him... then send him a nasty gram.  It will show up as coming from him, and to him... and unless he knows how to read headers, he'll be one confused cookie.
 
-pat-
 
 
----- Original Message -----
Sent: Monday, August 11, 2003 8:00 PM
Subject: RE: [IMail Forum] Telnet to port 25

�Relay for Local Users� is also known as OPEN RELAY.

 

Only secure settings are no relay or relay for addresses.

 

That will keep him off the server, unless he knows the password to an e-mail account on your server.

 

John Tolmachoff MCSE CSSA

Engineer/Consultant

eServices For You

www.eservicesforyou.com

 

-----Original Message-----
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of B.H.(pat) Forbes
Sent:
Monday, August 11, 2003 5:34 PM
To: [EMAIL PROTECTED]
Subject: [IMail Forum] Telnet to port 25

 

How do I stop someone from telneting to port 25 and then creating a new email?

 

I have security set to "relay for local users" but, have tried every possible security option and it still allows jo-blow from anywhwre to login and send mail.  All he has to do is use a valid email address thats on the server (ie.  [EMAIL PROTECTED])

 

helo mydomainname.com  (any domain name works)

mail from:[EMAIL PROTECTED]  (he's now spoofed my email address)

rcpt to:[EMAIL PROTECTED] (any email address he wants)

 

at this point, all he needs to do is the data command, and he's sending email.

 

surely there is a way to keep him off the server or, a way to keep him from being able to do this??

 

-pat-

 

Reply via email to