Re: SMTP server vs open relay

"Mike Easter" <[email protected]>
Newsgroups gmane.mail.spam.spamcop.geeks
Organization SpamCop
Message-ID <[email protected]>
Brad White wrote:
> "Mike Easter"
>> Brad White wrote:
>>> I sometimes use an external e-mail account besides my company
>>> account to help keep mail sorted.
>>>
>>> Our local SMTP server locked up and had to be rebooted.
>>> As a result (don't ask, long confusing story) my IT admin had
>>> me install IIS and setup a local SMTP server on my local machine.

>> Does that mean that you are on a company network,
                           <notice I put an empty line in there for you>
> Yes.

> I know that ShieldsUp from GRC says that I'm invisible, but
> I'm pretty sure that doens't account for open relays and SMTP servers.

If you are invisible to shieldsup, you are pretty invisible.

> Um, not sure.  The only evidence I have that might apply here is from
> when I sent a test e-mail to another IP.  He said that it appeared to
> come from a RoadRunner business class IP address.
> My SMTP server is set up with a 10.2 address.

Yes I understand that.  I can see your posting IP is a west.biz.rr.com
IP.  With residential rr/s one can tell the geography a lot better.
With biz, it is harder.  I can see a tracert going thru' KC [Kansas
City] and NE [Nebraska] rr/s.  That doesn't have anything to do with
this thread, just an observation.  The 10.2 IP is just your internal
non-routing one.

>> To get it to work, I had to turn on relaying.  Now I can send and
>>> receive e-mail and everything seems to be working fine.

Hopefully someone familiar with IIS will jump in here and comment on
that.  I'm not sure I understand what 'relaying' is going on in this
context.  You are sending a mail to your IIS server which is relaying it
to wherever it is going, presumably.

> I've been able to receive e-mail to this account all along.  It is
> only sending that has been a problem.  I *believe* that I'm only using
> the SMTP server for sending e-mail.  I don't believe that it is
> involved in the receiving end of things.

I hear what you are saying and I'm not hearing something there that is
worrisome to me about someone outside accessing your server.  However, I
can imagine some scenarios by which you could propagate viruses if you
were infected.  I don't think I can imagine a scenario by which you
become trojanized and become a proxy for someone accessing your IP and
using it to inject smtp.

>> Now you can send and receive email from whom or what?

> Good question.

> I've been able to set the outgoing SMTP server to my local
> 10.2 address, and the mail goes out.  I'm assuming that the
> SMTP server that I set up is handling the outgoing mail.
> This is confirmed by the log files.  I can see the messages from
> interacting with the remote mail servers for messages I sent.
>
>> You can receive email from dynamic IPs direct to mx?

> How would I know?

Well, one way would be to look at your spam's headers.  Very frequently
there would be a spamsource sending directly to some MX which put the
item into your mailbox.  But maybe that's not important for this
discussion.

>> You have your own MX inside of the company's network?

> I don't think I set one up, but I assume, based on no evidence, that
> we have one.
> How would I know?

I guess one question would be how do you get your mail.  Not the
username, but how is mail addressed to 'you' -- where only the username
half is munged.  Knowing the domainname you receive mail might help
complete some missing parts of this discussion.

>> Your mail is routed into the company's network past
>> the firewall?  None of the above?

> Um, my vague understanding is that the SMTP server doesn't *actually*
> send anything.  It appears to notify the receiver at the destination
> which then requests the message from the SMTP server.

I don't think so, Tim [Al Borland - Tool Time - TV show]

>>> Now I'm being accused of being a problem because I have relaying
>>> turned on.

Could you elaborate more on how you came about to be accused of being a
problem?

>>> A tech from my e-mail provider tried to relay something through
>>> my SMTP server and couldn't even see it, so he thinks I'm safe,

Yes, that's my thinking so far.

>>> but I'd like something more athoritative that I could show the admin
>>> to calm him down.

The admin is edgy?  Could you explain that [why] a little better?

>>> How do I prove that this SMTP server can't be used as an open relay?

> Hmm.  I was hoping there was some more definite way to test for
> an open relay than trusting to my knowlege of the network setup.

If I want to 'mess around' with a server, I first try to hook up with it
by its name, alternatively by its IP.  So, I would engage it over its
port 25 and then see if I can fool it into relaying some for me.  If I
can't connect with it, I'm going to have a problem messing with it.

> I'll post again with my settings as they relate to this web page.


-- 
Mike Easter
kibitzer, not SC admin
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.