Re: Allowing relaying, but not opening a hole

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Drew (drew.laing_at_NOswvtc.dmhmrsas.virginia.SPMgov)
Date: 03/17/05


Date: Thu, 17 Mar 2005 12:49:56 -0500

And I lock this down on IIS or Exchange? Just checking, I am a programmer,
not so much administrator!

Thanks,
Drew

"Jason Brown [MSFT]" <i-brjaso@online.microsoft.com> wrote in message
news:OFT%23lcuKFHA.2936@TK2MSFTNGP15.phx.gbl...
> Personally, I lock down the 'connection control' section so that only
> 127.0.0.1 can connect at all. You can lock this down a few ways, but this
> is the simplest, IMO. However it doesn't protect against malware running
> on the local machine, which is a slight possibility in some
> configurations.
>
>
> --
> Jason Brown
> Microsoft GTSC, IIS
>
> This posting is provided "AS IS" with no warranties, and confers no
> rights.
>
> "Drew" <drew.laing@NOswvtc.dmhmrsas.virginia.SPMgov> wrote in message
> news:unrFm8mKFHA.2764@tk2msftngp13.phx.gbl...
>> It seems to me that in order to send email using ASP that you have to
>> have a COM to do it. This requires that you enable relaying, but that
>> opens up a hole. How can I get this accomplished without getting hacked?
>> I have ASPEmail installed (CDO was giving me problems), and I have to
>> enable relaying to send mail. Is this just a huge paradox? If not, can
>> you please let me know how to allow relaying, but not be vulnerable.
>>
>> Thanks,
>> Drew Laing
>>
>
>



Relevant Pages

  • Re: IIS 6 Locks Up, Must Restart, No Event Errors
    ... You can use IIS State to diagnose what is causing IIS to "Lock up", ... license comes with a car to drive -- you still have to buy/maintain the car. ... you have constructed a custom server package after purchasing ...
    (microsoft.public.inetserver.iis)
  • HTTPS working (I think) but Security lock not showing in IE
    ... I have an IIS 6 Server that I have just inherited (the system admin just ... I have a directory that needs to be SSL protected. ... The file starts off showing the lock, but by the time the file is ...
    (microsoft.public.inetserver.iis.security)
  • Re: Avoid users using OWA Backend?
    ... I'm assuming i lock that down in the IIS properties ... having some issues in the past if I made modifications through the IIS ... as opposed to the Exchange System Manager.... ... >> server simply proxies the request to the BE, ...
    (microsoft.public.exchange.admin)
  • Re: Avoid users using OWA Backend?
    ... this is something you would change through IIS. ... I'm assuming i lock that down in the IIS properties ... as opposed to the Exchange System Manager.... ... >> You can restrict access to the IIS Virtual Server. ...
    (microsoft.public.exchange.admin)
  • Re: Allowing relaying, but not opening a hole
    ... I lock down the 'connection control' section so that only ... This requires that you enable relaying, but that opens up> a hole. ... I have> ASPEmail installed, and I have to enable> relaying to send mail. ... > Drew Laing ...
    (microsoft.public.inetserver.iis.smtp_nntp)