Re: SMTP server vs open relay
"Mike Easter" <[email protected]>
| Newsgroups | gmane.mail.spam.spamcop.geeks |
|---|---|
| Organization | SpamCop |
| Message-ID | <[email protected]> |
Brad White wrote:
> "Mike Easter"
>> Brad White wrote:
>>> I sometimes use an external e-mail account besides my company
>>> account to help keep mail sorted.
>>>
>>> Our local SMTP server locked up and had to be rebooted.
>>> As a result (don't ask, long confusing story) my IT admin had
>>> me install IIS and setup a local SMTP server on my local machine.
>> Does that mean that you are on a company network,
<notice I put an empty line in there for you>
> Yes.
> I know that ShieldsUp from GRC says that I'm invisible, but
> I'm pretty sure that doens't account for open relays and SMTP servers.
If you are invisible to shieldsup, you are pretty invisible.
> Um, not sure. The only evidence I have that might apply here is from
> when I sent a test e-mail to another IP. He said that it appeared to
> come from a RoadRunner business class IP address.
> My SMTP server is set up with a 10.2 address.
Yes I understand that. I can see your posting IP is a west.biz.rr.com
IP. With residential rr/s one can tell the geography a lot better.
With biz, it is harder. I can see a tracert going thru' KC [Kansas
City] and NE [Nebraska] rr/s. That doesn't have anything to do with
this thread, just an observation. The 10.2 IP is just your internal
non-routing one.
>> To get it to work, I had to turn on relaying. Now I can send and
>>> receive e-mail and everything seems to be working fine.
Hopefully someone familiar with IIS will jump in here and comment on
that. I'm not sure I understand what 'relaying' is going on in this
context. You are sending a mail to your IIS server which is relaying it
to wherever it is going, presumably.
> I've been able to receive e-mail to this account all along. It is
> only sending that has been a problem. I *believe* that I'm only using
> the SMTP server for sending e-mail. I don't believe that it is
> involved in the receiving end of things.
I hear what you are saying and I'm not hearing something there that is
worrisome to me about someone outside accessing your server. However, I
can imagine some scenarios by which you could propagate viruses if you
were infected. I don't think I can imagine a scenario by which you
become trojanized and become a proxy for someone accessing your IP and
using it to inject smtp.
>> Now you can send and receive email from whom or what?
> Good question.
> I've been able to set the outgoing SMTP server to my local
> 10.2 address, and the mail goes out. I'm assuming that the
> SMTP server that I set up is handling the outgoing mail.
> This is confirmed by the log files. I can see the messages from
> interacting with the remote mail servers for messages I sent.
>
>> You can receive email from dynamic IPs direct to mx?
> How would I know?
Well, one way would be to look at your spam's headers. Very frequently
there would be a spamsource sending directly to some MX which put the
item into your mailbox. But maybe that's not important for this
discussion.
>> You have your own MX inside of the company's network?
> I don't think I set one up, but I assume, based on no evidence, that
> we have one.
> How would I know?
I guess one question would be how do you get your mail. Not the
username, but how is mail addressed to 'you' -- where only the username
half is munged. Knowing the domainname you receive mail might help
complete some missing parts of this discussion.
>> Your mail is routed into the company's network past
>> the firewall? None of the above?
> Um, my vague understanding is that the SMTP server doesn't *actually*
> send anything. It appears to notify the receiver at the destination
> which then requests the message from the SMTP server.
I don't think so, Tim [Al Borland - Tool Time - TV show]
>>> Now I'm being accused of being a problem because I have relaying
>>> turned on.
Could you elaborate more on how you came about to be accused of being a
problem?
>>> A tech from my e-mail provider tried to relay something through
>>> my SMTP server and couldn't even see it, so he thinks I'm safe,
Yes, that's my thinking so far.
>>> but I'd like something more athoritative that I could show the admin
>>> to calm him down.
The admin is edgy? Could you explain that [why] a little better?
>>> How do I prove that this SMTP server can't be used as an open relay?
> Hmm. I was hoping there was some more definite way to test for
> an open relay than trusting to my knowlege of the network setup.
If I want to 'mess around' with a server, I first try to hook up with it
by its name, alternatively by its IP. So, I would engage it over its
port 25 and then see if I can fool it into relaying some for me. If I
can't connect with it, I'm going to have a problem messing with it.
> I'll post again with my settings as they relate to this web page.
--
Mike Easter
kibitzer, not SC admin