Re: IIS SMTP - is open relay prevented?



Alternatively, if there's only a single web application, and this is
compromised, then you gain very little from SMTP AUTH since the
attacker is merely manipulating what the web application is
permitted to do anyway.

While you're right about this case, I hardly think this mitigates the
correctness of defensive design for a public-facing web server.

And just because you have a single-purpose web application doesn't
mean it reuses the same set of credentials for every session. An app
that uses HTTP auth, or any internal auth mechanism, that shares the
local SAM or AD and uses it for impersonation/isolation should also
pass those most specific credentials to the SMTP server. Maybe I'm
getting out of the real world here, but I firmly believe in the most
accountability possible to combat SMTP abuse, as it can be so
devastating to a server's global rep.

--Sandy


------------------------------------
Sanford Whiteman, Chief Technologist
Broadleaf Systems, a division of
Cypress Integrated Systems, Inc.
------------------------------------
.



Relevant Pages

  • Re: SBS 2003 Smart host
    ... only bad thing is that that i need to setup my other mail server ... Just try to google string "The remote SMTP service rejected AUTH negotiation". ... but hell with exchange 2003 sbs server is painfull. ...
    (microsoft.public.exchange.admin)
  • Re: 2 sites and auth smtp
    ... I have auth setup using my a Dedicated SMTP virtual off of one of my ... site are connected over a WAN and each server has his own routing group. ... The company, which had installed the Exchange servers, said configuring ...
    (microsoft.public.exchange.connectivity)
  • Re: Relayberechtigungen einrichten
    ... erfolgreich auth. ... smtp Dienst neu starten). ... Kurze Beschreibung wie man an diversen Clients SMTP AUTH verwenden ... Next by Date: ...
    (microsoft.public.de.exchange)
  • Re: SMTP Logging
    ... Hallo Sascha, ... Dein Provider macht sicher entweder SMTP Auth oder POP before SMTP. ... Bei SMTP Auth kriegst Du genau die Fehlermeldung, wenn Dein Exchange ...
    (microsoft.public.de.exchange)
  • Re: Postifx as SMTP AUTH client
    ... I've configured Postfix ... How could the AUTH command be disabled at ... If you have to setup SMTP ... problem lies elsewhere in your postfix config. ...
    (Fedora)