OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: steverfyiowa.com
Date: Thu Jan 03 2002 - 16:11:39 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    We do the same thing with Sendmail for NT on a server in the DMZ. It then
    relays the mail to Exchange inside the firewall.

    -----Original Message-----
    From: SteveFdice.com [mailto:SteveFdice.com]
    Sent: Thursday, January 03, 2002 8:02 AM
    To: focus-mssecurityfocus.com
    Subject: RE: Exchange 5.5 locking down

    > My solution was to just start using the sniffer ethereal. It
    > will do smtp
    > decodes so you can see the whole message, headers, etc
    > without worrying
    > about MS exchange logging, plus you can use it whenever you
    > please and in
    > some cases dont even have to touch the exchage server (if you
    > are on a hub
    > or somwhere that is easily sniffable).

    I realize that this is an MS focused list, but my solution to the spamming
    problem was to funnel all incoming email into Linux host running sendmail,
    which virus scans and rejects mail based on originating IP, and has the
    capability to reject based on content as well, though we do not do that. We
    can also use this machine to query the Realtime Blackhole List (RBL) for
    known spamming sources and reject them automatically. This is another
    feature that we are currently not using. Doing this has taken a bit of the
    load of dealing with the SPAM off of my Exchange server.

    Steve Fuller