Solved

Change SMTP banner

Posted on 2014-11-19
11
198 Views
Last Modified: 2015-01-22
Hello,

We are a financial institution and every year we have an outside company come in and do a security assessment on our systems.  A couple of the items that need remediation involve changing our SMTP banner that is permitting user enumeration and discloses our internal domain name.  We are a Windows network (Server 03 and 08) running MDaemon as our email service.  If any more information is needed, please let me know.  We also utilize Cisco Ironport email and web gateway devices.

Thanks,
Cheese
0
Comment
Question by:cheesebugah
  • 6
  • 3
  • 2
11 Comments
 
LVL 37

Expert Comment

by:Neil Russell
ID: 40453365
Your SMTP banner alone can not allow enumeration of users!
Your smtp banner should match your A record for your mail server.  You should also have a correctly configured reverse DNS record that this will utilise to help avoid spam on the internet.  More and more mail providers and ISPs and using reverse DNS mismatch as a reason to reject your outgoing email as spam.

Did they advise you what to set it to?
0
 
LVL 33

Expert Comment

by:it_saige
ID: 40453425
I agree with Neilsr.  Saying that the SMTP banner allows the enumeration of users is like saying that the house address allows enumeration of the occupants.

If the doors are locked and windows covered, you cannot know how many people are occupying a house simply because you have the address.

However, the internal domain name is an issue.  The smtp banner should answer with "mail.yourdomain.com" and not "mailserver.yourdomain.local".  

-saige-
0
 

Author Comment

by:cheesebugah
ID: 40453570
Here is the remediation recommendation:

Disable the VRFY and EXPN commands. If feasible, configure the host to respond identically to requests to send to both legitimate user mailboxes and non-existent mailboxes.  Messages to non-existent mailboxes can be silently dropped later without generating a non-delivery report, which may also inform a potential attacker about which usernames are valid.

Thanks,
Cheese
0
 
LVL 37

Accepted Solution

by:
Neil Russell earned 250 total points
ID: 40453600
"Disable the VRFY and EXPN commands" Yep thats standard security practice on a Linux mail server.

I dont see anything there about SMTP Banners though?

Standard practice again to just DROP main to non existent addresses.  If you get spammed to 10,000 mail addresses and the spammer gets 99990 NDR's back then he now has 10 real addresses to work on.  Tell nobody anything.
0
 
LVL 33

Assisted Solution

by:it_saige
it_saige earned 250 total points
ID: 40453612
In other words, don't send back replies for non-existent addresses.  If a (would you call them spammers??? In my mind they are trying to get a list of addresses to spoof) spammer/spoofer gets back NDRs, you are telling them which addresses are valid and which addresses are not.

-saige-
0
U.S. Department of Agriculture and Acronis Access

With the new era of mobile computing, smartphones and tablets, wireless communications and cloud services, the USDA sought to take advantage of a mobilized workforce and the blurring lines between personal and corporate computing resources.

 

Author Comment

by:cheesebugah
ID: 40453653
Okay, I was slightly askew on the SMTP banner issue.  Our internal domain name is disclosed by the banner.  On the user enumeration issue, the assessor used telnet to mail.domain.com on port 25 and it revealed valid email addresses.
0
 
LVL 37

Expert Comment

by:Neil Russell
ID: 40453668
yes because of "Disable the VRFY and EXPN commands" not being done before now.
0
 

Author Comment

by:cheesebugah
ID: 40453694
Neilsr,

How would I disable those commands?  I am using an Ironport email gateway and MDaemon as the email service.  I see that the "Add Received Header" is checked in the Listener.
0
 

Author Comment

by:cheesebugah
ID: 40489479
I have a support call with Cisco on this and will report back when I get an answer.
0
 

Author Comment

by:cheesebugah
ID: 40560368
This SMTP banner can be modified under Mail Policies>Mail Flow Policies>Default Parameters on an Ironport C160 email gateway appliance.

Thanks,
Mike
0
 

Author Closing Comment

by:cheesebugah
ID: 40565240
Thank you very much.
0

Featured Post

Ransomware-A Revenue Bonanza for Service Providers

Ransomware – malware that gets on your customers’ computers, encrypts their data, and extorts a hefty ransom for the decryption keys – is a surging new threat.  The purpose of this eBook is to educate the reader about ransomware attacks.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Phishing is at the top of most security top 10 efforts you should be pursuing in 2016 and beyond. If you don't have phishing incorporated into your Security Awareness Program yet, now is the time. Phishers, and the scams they use, are only going to …
I've been an avid user and supporter of Malwarebytes Premium Version 2.x for years. It's an excellent product that runs alongside just about any Anti-Virus application without issues. It seems to have an uncanny ability to pick up many things that A…
A short film showing how OnPage and Connectwise integration works.
A company’s greatest vulnerability is their email. CEO fraud, ransomware and spear phishing attacks are the no1 threat to a company’s security. Cybercrime is responsible for the largest loss of money to companies today with losses projected to r…

930 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now