RE: IIS SMTP component allows mail relaying via Null Session

From: Toni Lassila (toni.lassila@mc-europe.com)
Date: Sun Mar 03 2002 - 22:13:03 PST

  • Next message: Ben Laurie: "Apache-SSL 1.3.22+1.47 - update to security fix"

    > -----Original Message-----
    > From: Todd Sabin [mailto:tsabinat_private]
    > Sent: Friday, March 01, 2002 17:31
    > To: bugtraqat_private
    > Subject: IIS SMTP component allows mail relaying via Null Session
    >
    > Overview:
    > IIS comes with a small SMTP component.  The default settings allow
    > anyone who can authenticate to it to relay email.  Because the
    > authentication system supports NTLM, it is possible for anyone to
    > authenticate using null session credentials, and then relay email.
    > 
    > Workarounds:
    > Disable the SMTP service.
    > Disable the ability of authenticated users to relay email.
    > Firewall off the SMTP service from untrusted networks.
    
    I suspect turning off NTLM authentication and allowing only Basic
    Authentication (with or without TLS), or alternatively disabling
    null session access (details are in many MS KB) from the server
    are two possible workarounds as well. Disabling null sessions is
    one of those security features one should do when securing a
    Windows-based server anyway.
    
    -- 
    Toni Lassila         t.lassila@mc-europe.com
    Operations Engineer         +358 9 5655 1882
    
    
    



    This archive was generated by hypermail 2b30 : Mon Mar 04 2002 - 15:19:15 PST