cheesebugah
asked on
Change SMTP banner
Hello,
We are a financial institution and every year we have an outside company come in and do a security assessment on our systems. A couple of the items that need remediation involve changing our SMTP banner that is permitting user enumeration and discloses our internal domain name. We are a Windows network (Server 03 and 08) running MDaemon as our email service. If any more information is needed, please let me know. We also utilize Cisco Ironport email and web gateway devices.
Thanks,
Cheese
We are a financial institution and every year we have an outside company come in and do a security assessment on our systems. A couple of the items that need remediation involve changing our SMTP banner that is permitting user enumeration and discloses our internal domain name. We are a Windows network (Server 03 and 08) running MDaemon as our email service. If any more information is needed, please let me know. We also utilize Cisco Ironport email and web gateway devices.
Thanks,
Cheese
I agree with Neilsr. Saying that the SMTP banner allows the enumeration of users is like saying that the house address allows enumeration of the occupants.
If the doors are locked and windows covered, you cannot know how many people are occupying a house simply because you have the address.
However, the internal domain name is an issue. The smtp banner should answer with "mail.yourdomain.com" and not "mailserver.yourdomain.loc al".
-saige-
If the doors are locked and windows covered, you cannot know how many people are occupying a house simply because you have the address.
However, the internal domain name is an issue. The smtp banner should answer with "mail.yourdomain.com" and not "mailserver.yourdomain.loc
-saige-
ASKER
Here is the remediation recommendation:
Disable the VRFY and EXPN commands. If feasible, configure the host to respond identically to requests to send to both legitimate user mailboxes and non-existent mailboxes. Messages to non-existent mailboxes can be silently dropped later without generating a non-delivery report, which may also inform a potential attacker about which usernames are valid.
Thanks,
Cheese
Disable the VRFY and EXPN commands. If feasible, configure the host to respond identically to requests to send to both legitimate user mailboxes and non-existent mailboxes. Messages to non-existent mailboxes can be silently dropped later without generating a non-delivery report, which may also inform a potential attacker about which usernames are valid.
Thanks,
Cheese
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
Okay, I was slightly askew on the SMTP banner issue. Our internal domain name is disclosed by the banner. On the user enumeration issue, the assessor used telnet to mail.domain.com on port 25 and it revealed valid email addresses.
yes because of "Disable the VRFY and EXPN commands" not being done before now.
ASKER
Neilsr,
How would I disable those commands? I am using an Ironport email gateway and MDaemon as the email service. I see that the "Add Received Header" is checked in the Listener.
How would I disable those commands? I am using an Ironport email gateway and MDaemon as the email service. I see that the "Add Received Header" is checked in the Listener.
ASKER
I have a support call with Cisco on this and will report back when I get an answer.
ASKER
This SMTP banner can be modified under Mail Policies>Mail Flow Policies>Default Parameters on an Ironport C160 email gateway appliance.
Thanks,
Mike
Thanks,
Mike
ASKER
Thank you very much.
Your smtp banner should match your A record for your mail server. You should also have a correctly configured reverse DNS record that this will utilise to help avoid spam on the internet. More and more mail providers and ISPs and using reverse DNS mismatch as a reason to reject your outgoing email as spam.
Did they advise you what to set it to?