Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

Change SMTP banner

Posted on 2014-11-19
11
Medium Priority
?
248 Views
Last Modified: 2015-01-22
Hello,

We are a financial institution and every year we have an outside company come in and do a security assessment on our systems.  A couple of the items that need remediation involve changing our SMTP banner that is permitting user enumeration and discloses our internal domain name.  We are a Windows network (Server 03 and 08) running MDaemon as our email service.  If any more information is needed, please let me know.  We also utilize Cisco Ironport email and web gateway devices.

Thanks,
Cheese
0
Comment
Question by:cheesebugah
  • 6
  • 3
  • 2
11 Comments
 
LVL 37

Expert Comment

by:Neil Russell
ID: 40453365
Your SMTP banner alone can not allow enumeration of users!
Your smtp banner should match your A record for your mail server.  You should also have a correctly configured reverse DNS record that this will utilise to help avoid spam on the internet.  More and more mail providers and ISPs and using reverse DNS mismatch as a reason to reject your outgoing email as spam.

Did they advise you what to set it to?
0
 
LVL 35

Expert Comment

by:it_saige
ID: 40453425
I agree with Neilsr.  Saying that the SMTP banner allows the enumeration of users is like saying that the house address allows enumeration of the occupants.

If the doors are locked and windows covered, you cannot know how many people are occupying a house simply because you have the address.

However, the internal domain name is an issue.  The smtp banner should answer with "mail.yourdomain.com" and not "mailserver.yourdomain.local".  

-saige-
0
 

Author Comment

by:cheesebugah
ID: 40453570
Here is the remediation recommendation:

Disable the VRFY and EXPN commands. If feasible, configure the host to respond identically to requests to send to both legitimate user mailboxes and non-existent mailboxes.  Messages to non-existent mailboxes can be silently dropped later without generating a non-delivery report, which may also inform a potential attacker about which usernames are valid.

Thanks,
Cheese
0
The Growing Need for Data Analysts

As the amount of data rapidly increases in our world, so does the need for qualified data analysts. WGU's MS in Data Analytics and maximize your leadership opportunities as a data engineer, business analyst, information research scientist, and more.

 
LVL 37

Accepted Solution

by:
Neil Russell earned 1000 total points
ID: 40453600
"Disable the VRFY and EXPN commands" Yep thats standard security practice on a Linux mail server.

I dont see anything there about SMTP Banners though?

Standard practice again to just DROP main to non existent addresses.  If you get spammed to 10,000 mail addresses and the spammer gets 99990 NDR's back then he now has 10 real addresses to work on.  Tell nobody anything.
0
 
LVL 35

Assisted Solution

by:it_saige
it_saige earned 1000 total points
ID: 40453612
In other words, don't send back replies for non-existent addresses.  If a (would you call them spammers??? In my mind they are trying to get a list of addresses to spoof) spammer/spoofer gets back NDRs, you are telling them which addresses are valid and which addresses are not.

-saige-
0
 

Author Comment

by:cheesebugah
ID: 40453653
Okay, I was slightly askew on the SMTP banner issue.  Our internal domain name is disclosed by the banner.  On the user enumeration issue, the assessor used telnet to mail.domain.com on port 25 and it revealed valid email addresses.
0
 
LVL 37

Expert Comment

by:Neil Russell
ID: 40453668
yes because of "Disable the VRFY and EXPN commands" not being done before now.
0
 

Author Comment

by:cheesebugah
ID: 40453694
Neilsr,

How would I disable those commands?  I am using an Ironport email gateway and MDaemon as the email service.  I see that the "Add Received Header" is checked in the Listener.
0
 

Author Comment

by:cheesebugah
ID: 40489479
I have a support call with Cisco on this and will report back when I get an answer.
0
 

Author Comment

by:cheesebugah
ID: 40560368
This SMTP banner can be modified under Mail Policies>Mail Flow Policies>Default Parameters on an Ironport C160 email gateway appliance.

Thanks,
Mike
0
 

Author Closing Comment

by:cheesebugah
ID: 40565240
Thank you very much.
0

Featured Post

Identify and Prevent Potential Cyber-threats

Become the white hat who helps safeguard our interconnected world. Transform your career future by earning your MS in Cybersecurity. WGU’s MSCSIA degree program was designed in collaboration with national intelligence organizations and IT industry leaders.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

We aren’t perfect, just like everyone else.  Check out the email errors our community caught and learn the top errors every email marketer should avoid.
Phishing emails are a popular malware delivery vehicle for attack.  While there are many ways for an attacker to increase the chances of success for their phishing emails, one of the most effective methods involves spoofing the message to appear to …
If you're a developer or IT admin, you’re probably tasked with managing multiple websites, servers, applications, and levels of security on a daily basis. While this can be extremely time consuming, it can also be frustrating when systems aren't wor…
We’ve all felt that sense of false security before—locking down external access to a database or component and feeling like we’ve done all we need to do to secure company data. But that feeling is fleeting. Attacks these days can happen in many w…

572 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question