Solved

Change SMTP banner

Posted on 2014-11-19
11
211 Views
Last Modified: 2015-01-22
Hello,

We are a financial institution and every year we have an outside company come in and do a security assessment on our systems.  A couple of the items that need remediation involve changing our SMTP banner that is permitting user enumeration and discloses our internal domain name.  We are a Windows network (Server 03 and 08) running MDaemon as our email service.  If any more information is needed, please let me know.  We also utilize Cisco Ironport email and web gateway devices.

Thanks,
Cheese
0
Comment
Question by:cheesebugah
  • 6
  • 3
  • 2
11 Comments
 
LVL 37

Expert Comment

by:Neil Russell
ID: 40453365
Your SMTP banner alone can not allow enumeration of users!
Your smtp banner should match your A record for your mail server.  You should also have a correctly configured reverse DNS record that this will utilise to help avoid spam on the internet.  More and more mail providers and ISPs and using reverse DNS mismatch as a reason to reject your outgoing email as spam.

Did they advise you what to set it to?
0
 
LVL 33

Expert Comment

by:it_saige
ID: 40453425
I agree with Neilsr.  Saying that the SMTP banner allows the enumeration of users is like saying that the house address allows enumeration of the occupants.

If the doors are locked and windows covered, you cannot know how many people are occupying a house simply because you have the address.

However, the internal domain name is an issue.  The smtp banner should answer with "mail.yourdomain.com" and not "mailserver.yourdomain.local".  

-saige-
0
 

Author Comment

by:cheesebugah
ID: 40453570
Here is the remediation recommendation:

Disable the VRFY and EXPN commands. If feasible, configure the host to respond identically to requests to send to both legitimate user mailboxes and non-existent mailboxes.  Messages to non-existent mailboxes can be silently dropped later without generating a non-delivery report, which may also inform a potential attacker about which usernames are valid.

Thanks,
Cheese
0
VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

 
LVL 37

Accepted Solution

by:
Neil Russell earned 250 total points
ID: 40453600
"Disable the VRFY and EXPN commands" Yep thats standard security practice on a Linux mail server.

I dont see anything there about SMTP Banners though?

Standard practice again to just DROP main to non existent addresses.  If you get spammed to 10,000 mail addresses and the spammer gets 99990 NDR's back then he now has 10 real addresses to work on.  Tell nobody anything.
0
 
LVL 33

Assisted Solution

by:it_saige
it_saige earned 250 total points
ID: 40453612
In other words, don't send back replies for non-existent addresses.  If a (would you call them spammers??? In my mind they are trying to get a list of addresses to spoof) spammer/spoofer gets back NDRs, you are telling them which addresses are valid and which addresses are not.

-saige-
0
 

Author Comment

by:cheesebugah
ID: 40453653
Okay, I was slightly askew on the SMTP banner issue.  Our internal domain name is disclosed by the banner.  On the user enumeration issue, the assessor used telnet to mail.domain.com on port 25 and it revealed valid email addresses.
0
 
LVL 37

Expert Comment

by:Neil Russell
ID: 40453668
yes because of "Disable the VRFY and EXPN commands" not being done before now.
0
 

Author Comment

by:cheesebugah
ID: 40453694
Neilsr,

How would I disable those commands?  I am using an Ironport email gateway and MDaemon as the email service.  I see that the "Add Received Header" is checked in the Listener.
0
 

Author Comment

by:cheesebugah
ID: 40489479
I have a support call with Cisco on this and will report back when I get an answer.
0
 

Author Comment

by:cheesebugah
ID: 40560368
This SMTP banner can be modified under Mail Policies>Mail Flow Policies>Default Parameters on an Ironport C160 email gateway appliance.

Thanks,
Mike
0
 

Author Closing Comment

by:cheesebugah
ID: 40565240
Thank you very much.
0

Featured Post

Announcing the Most Valuable Experts of 2016

MVEs are more concerned with the satisfaction of those they help than with the considerable points they can earn. They are the types of people you feel privileged to call colleagues. Join us in honoring this amazing group of Experts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Phishing is at the top of most security top 10 efforts you should be pursuing in 2016 and beyond. If you don't have phishing incorporated into your Security Awareness Program yet, now is the time. Phishers, and the scams they use, are only going to …
Ransomware continues to be a growing problem for both personal and business users alike and Antivirus companies are still struggling to find a reliable way to protect you from this dangerous threat.
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…

839 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question