Re: SMTP server vs open relay

"Brad White" <[email protected]>
Newsgroups gmane.mail.spam.spamcop.geeks
Organization SpamCop
Message-ID <[email protected]>
"Mike Easter" <[email protected]> wrote in message 
news:[email protected]...
> Brad White wrote:
>> "Mike Easter"
>>> Brad White wrote:
>>>> I sometimes use an external e-mail account besides my company
>>>> account to help keep mail sorted.

>> I know that ShieldsUp from GRC says that I'm invisible, but
>> I'm pretty sure that doens't account for open relays and SMTP servers.
>
> If you are invisible to shieldsup, you are pretty invisible.

OK.

>> Um, not sure.  The only evidence I have that might apply here is from
>> when I sent a test e-mail to another IP.  He said that it appeared to
>> come from a RoadRunner business class IP address.
>> My SMTP server is set up with a 10.2 address.
>
> Yes I understand that.  I can see your posting IP is a west.biz.rr.com
> IP.  With residential rr/s one can tell the geography a lot better.
> With biz, it is harder.  I can see a tracert going thru' KC [Kansas
> City] and NE [Nebraska] rr/s.  That doesn't have anything to do with
> this thread, just an observation.  The 10.2 IP is just your internal
> non-routing one.

Yes.
>
>>> To get it to work, I had to turn on relaying.  Now I can send and
>>>> receive e-mail and everything seems to be working fine.
>
> Hopefully someone familiar with IIS will jump in here and comment on
> that.  I'm not sure I understand what 'relaying' is going on in this
> context.

I'm surprised that I need to turn relaying on.  This seems to me to be
the least relaying situation possible.  If I need relaying on for this,
it is hard to imagine a situation that woudl not need it.

> You are sending a mail to your IIS server which is relaying it
> to wherever it is going, presumably.

Presumably.

>> I've been able to receive e-mail to this account all along.  It is
>> only sending that has been a problem.  I *believe* that I'm only using
>> the SMTP server for sending e-mail.  I don't believe that it is
>> involved in the receiving end of things.
>
> I hear what you are saying and I'm not hearing something there that is
> worrisome to me about someone outside accessing your server.  However, I
> can imagine some scenarios by which you could propagate viruses if you
> were infected.

Certainly.

> I don't think I can imagine a scenario by which you
> become trojanized and become a proxy for someone accessing your IP and
> using it to inject smtp.
>
Well, that's encouraging.

>>> You can receive email from dynamic IPs direct to mx?
>> How would I know?
> Well, one way would be to look at your spam's headers.  Very frequently
> there would be a spamsource sending directly to some MX which put the
> item into your mailbox.  But maybe that's not important for this
> discussion.
>

Spam coming to me for this account comes through my external ISP.
No internal mail servers show up in the Spamcop trace.

>>> Your mail is routed into the company's network past
>>> the firewall?  None of the above?
>
>> Um, my vague understanding is that the SMTP server doesn't *actually*
>> send anything.  It appears to notify the receiver at the destination
>> which then requests the message from the SMTP server.
>
> I don't think so, Tim [Al Borland - Tool Time - TV show]
>
>>>> Now I'm being accused of being a problem because I have relaying
>>>> turned on.
>
> Could you elaborate more on how you came about to be accused of being a
> problem?
>
Well, I'm not competely sure about that.  I had an existing e-mail account
through a local ISP.  After starting here, the ISP allowed me to keep the
account, but using the work ISP, for $29 a year.  At work they grudgingly
allowed me to access my external e-mail provider in addition to my work
e-mail.  I'm the only one, so I'm odd man out, so to speak.

I also have to be on a special list at the ISP, because they normally don't
allow mail that appears to be from their network, but really isn't, to go
to accounts on their network.  I'm an exception and have to be in an 
exception
list or go to the spam bucket.

A month ago, I realized that my outgoing e-mails were not actually going
out.  No errors, but no one was responding and I got a few reports that they
hadn't received my replies.
At first I assumed that it was a problem at my e-mail provider.  But they
couldn't find anything on that end.
I checked with my admin here, and *all* e-mail going through that server
had stopped.  Something was locked up.
Couldn't delete the emails in the outgoing que, since something still had
ahold of them.  We'll never know what.
We rebooted the server, and now everything is fine.

Not much e-mail actually goes through that SMTP server since everyone here
uses Outlook which goes through an Exchange server.

I can use that SMTP server IP as my OE outgoing SMTP server, and it works.
But, probably since I noticed and asked about it, I got blamed for locking 
it
up and blocking all the other e-mails from going out.  For all I know,
it could have been one of my e-mails that did it.  They were they same
simple text e-mails I've been sending hte same way for the last two years.

Enough of that.

>>>> A tech from my e-mail provider tried to relay something through
>>>> my SMTP server and couldn't even see it, so he thinks I'm safe,
>
> Yes, that's my thinking so far.
>
>>>> but I'd like something more athoritative that I could show the admin
>>>> to calm him down.
>
> The admin is edgy?  Could you explain that [why] a little better?

I think it's in his nature, probably aggravated by his experience, that
anything that can be exploited will be.  And that no one else knows
anything about security.  Which in my case would be close to the truth.
I know about application security, but not network security.  I depend
on the techs for that.

>
>>>> How do I prove that this SMTP server can't be used as an open relay?
>
>> Hmm.  I was hoping there was some more definite way to test for
>> an open relay than trusting to my knowlege of the network setup.
>
> If I want to 'mess around' with a server, I first try to hook up with it
> by its name, alternatively by its IP.  So, I would engage it over its
> port 25 and then see if I can fool it into relaying some for me.  If I
> can't connect with it, I'm going to have a problem messing with it.
>
So, if you wanted to use it as an open relay, you would have to
be able to see it from the net, and ShieldsUp says I'm invisible?
It definitely tried port 25.

-- 
Thanks,
Brad White
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.