Solved

Possibility of a whitelisted (Internet) IP address being spoofed

Posted on 2016-07-29
4
142 Views
Last Modified: 2016-08-01
Currently we don't permit Tcp25 from public Internet to our Exchange server:
all emails go to our internet-facing ProofPoint , then only ProofPoint forward
it our Exchange 2010 server

We plan to permit Tcp 25 direct into our local Exchange 2010 server from an
IP address ie whitelist this public IP address which is our HQ's ProofPoint IP:

a) if it's only a firewall rule that permit our HQ's ProofPoint IP to come in to
    our Exchange server, I guess this IP can be spoofed.  What if this IP is also
    whitelisted, can it be spoofed as well?  I read only Udp can be spoofed or
    is this mistaken?

b) is there any risk of MITM attack for this forwarding ?  The forwarded emails
     are not encrypted
0
Comment
Question by:sunhux
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 19

Accepted Solution

by:
Mal Osborne earned 250 total points
ID: 41734298
A) Probably not. A device spoofing your IP address would somehow need to be able to the routed from and too.

B) In theory, anyone who can get to see your traffic could implement a "Man in the middle" attack, unless encryption is used. Unencrypted email is not very secure.
0
 
LVL 96

Assisted Solution

by:Experienced Member
Experienced Member earned 250 total points
ID: 41734560
We plan to permit TCP 25 direct

At a client, my own consulting machine has a DHCP reservation and then that IP address is allowed in the Juniper firewall so that I may send out email separately from their email system.

I do not think you are at excessive risk for doing this. My machine does not compromise the client network.
0
 

Author Comment

by:sunhux
ID: 41734739
https://community.mimecast.com/docs/DOC-1419

Refer to above link: there are indications in the link that allude to IP addr spoofing:

Create an Anti-Spoofing Policy to Allow "Spoofing Based on IP"

5.Enter the list of hostnames to apply the bypass to in the Hostnames box. Confirmation is issued
   that the "IP address used by the sending server matches the hostname specified"
   ie for the protection to be effective, it needs both IP address plus hostname to match
0
 
LVL 96

Assisted Solution

by:Experienced Member
Experienced Member earned 250 total points
ID: 41735147
I looked quickly and will look again when I have time. If your firewall is otherwise properly locked down, open a port for one IP address only (not everyone) is not likely to cause harm.
0

Featured Post

What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

There are times when we need to generate a report on the inbox rules, where users have set up forwarding externally in their mailbox. In this article, I will be sharing a script I wrote to generate the report in CSV format.
With the rising number of cyber attacks in recent years, keeping your personal data safe has become more important than ever. The tips outlined in this article will help you keep your identitfy safe.
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…
NetCrunch network monitor is a highly extensive platform for network monitoring and alert generation. In this video you'll see a live demo of NetCrunch with most notable features explained in a walk-through manner. You'll also get to know the philos…

626 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question