Re: SMTP server vs open relay

"Brad White" <[email protected]>
Newsgroups gmane.mail.spam.spamcop.geeks
Organization SpamCop
Message-ID <[email protected]>
Mike asked some very good questions, most of which I don't
know the answer to.  My few comments are inline.

"Mike Easter" <[email protected]> wrote in message 
news:[email protected]...
> Brad White wrote:
>> I sometimes use an external e-mail account besides my company account
>> to help keep mail sorted.
>>
>> Our local SMTP server locked up and had to be rebooted.
>> As a result (don't ask, long confusing story) my IT admin had
>> me install IIS and setup a local SMTP server on my local machine.
>
> There are some implications in the network topology 'non-description'
> there that need to be clarified.
>
> Does that mean that you are on a company network,
Yes.

> and that company
> network is behind a genuine industrial strength firewall and is
> otherwise secured from the WAN internet at large?
>
That is my understanding, but I have no knowledge or proof of
how it is actually set up.  I know that if we get a lot of ping traffic
from a particular domain, the admin will block the entire domain.

I know that ShieldsUp from GRC says that I'm invisible, but
I'm pretty sure that doens't account for open relays and SMTP servers.

> Does that also mean that your *own* network or machine are/is behind its
> *own* NAT device or other hardware firewall?  I aks that because of a
> later statement you made about seeing your server.

Um, not sure.  The only evidence I have that might apply here is from
when I sent a test e-mail to another IP.  He said that it appeared to
come from a RoadRunner business class IP address.
My SMTP server is set up with a 10.2 address.

>
>> To get it to work, I had to turn on relaying.  Now I can send and
>> receive e-mail and everything seems to be working fine.
>
I've been able to receive e-mail to this account all along.  It is
only sending that has been a problem.  I *believe* that I'm only using
the SMTP server for sending e-mail.  I don't believe that it is involved
in the receiving end of things.
Sorry for the confusion.

> Now you can send and receive email from whom or what?
Good question.
I've been able to set the outgoing SMTP server to my local
10.2 address, and the mail goes out.  I'm assuming that the
SMTP server that I set up is handling the outgoing mail.
This is confirmed by the log files.  I can see the messages from
interacting with the remote mail servers for messages I sent.

> You can receive email from dynamic IPs direct to mx?
How would I know?

> You have your own MX inside of the company's network?
I don't think I set one up, but I assume, based on no evidence, that we have 
one.
How would I know?

> Your mail is routed into the company's network past
> the firewall?  None of the above?
Um, my vague understanding is that the SMTP server doesn't *actually*
send anything.  It appears to notify the receiver at the destination which
then requests the message from the SMTP server.  For that to be true,
the POP machine would have to be able to communicate with my machine.
How any of that navigates the firewall, I don't know.

Just noticed that IIS is listed as an exception for my local XP firewall.

I have no access or logon priveleges to the machines that handle that 
aspect.

I am running Windows XP, sp2.  The firewall is turned on.  No access to
SMTP is allowed (according to the settings) from the internet.
I do *not* have access to "local security policy" on my machine, so
I can't tell you the settings there.

>
>> Now I'm being accused of being a problem because I have relaying
>> turned on.
>
> No doubt that the IIS can be insecure.
Undoubtably.
What I'm trying to avoid is getting us listed on an RBL.  Then
I'd really be in trouble.     8:-)

>
>> I have it set to only allow mail from my IP, so I think
>> that I'm safe.
>
> That sounds good, except that we/I don't know/ can't tell/ what is set
> where behind what.
>
>> Now I just need to prove it.
>> A tech from my e-mail provider tried to relay something through
>> my SMTP server and couldn't even see it, so he thinks I'm safe,
>> but I'd like something more athoritative that I could show the admin
>> to calm him down.
>
> Now you can see why describing the network topology of your company and
> your IIS server as above is so important.  I can't even tell where the
> email provider is compared to anything else.
>
>> How do I prove that this SMTP server can't be used as an open relay?
>
> Start by describing for sake of discussion where everything is,
> network-wise, and what kinds of firewalls or NAT devices are where.
>
Hmm.  I was hoping there was some more definite way to test for
an open relay than trusting to my knowlege of the network setup.

> There's a IIS discussion here
> http://www.iis-resources.com/modules/AMS/article.php?storyid=5  how to
> set the SMTP Server security options.
>
That looked promising, but at the key points all it says is "depending on 
your setup."
No discussion about the effects of the various settings.

I'll post again with my settings as they relate to this web page.

Thanks,
Brad.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.