Re: sasl spam?

Matus UHLAR - fantomas <[email protected]> Mon, 7 Oct 2013 17:30:25 +0200
Newsgroups gmane.linux.debian.user.isp
Message-ID <[email protected]>
>Monday, October 7, 2013, 16:16:32, Matus UHLAR - fantomas wrote:
>> do you require or at least provide SSL/TLS encryption for SMTP users?
>> While possibility of such malware is quite high (there was already malware
>> stealing FTP passwords), it may not be able to sniff on encrypted
>> connections

On 07.10.13 16:55, Marek Podmaka wrote:
>Of course we have smtp/pop3/imap also over ssl/startls, alhough I
>don't have stats how many users do use it.

with e.g. courier MTA you can allowed plaintext authentication only with
encyphered connection.

> Malware can redirect the
>SMTP/IMAP connection to itself like many antivirus software does.

Using proper certificates could detect the MITM attack.

> Or maybe it sniffs on the local network, but I don't guess it's very
>effective in switched networks (hmm or maybe public wifi).

that's it...

>Good idea about requiring SSL/TLS. Is there any overview if there are
>clients/mobile devices actively in use which don't support it? For
>example will Outlook without SSL/TLS configured use it server will
>require it?

I have no idea if some clients don't support encryption, but I think it
would be worth trying...

>BTW the FTP stealing is still a threat, if I remember it steals
>passwords from Total Commander. That's why we enable FTP from exotic
>countries (geoip) only on request.

I haven't got to the requiring FTPS, since there aren't many clients
supporting that. However, if you provide scp/sftp access, it should be
already possible only to allow encyphered connections.

-- 
Matus UHLAR - fantomas, [email protected] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
"To Boot or not to Boot, that's the question." [WD1270 Caviar]