Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [Full-disclosure] Secure OWA |
|---|---|
| Date: | Sat, 26 Aug 2006 14:30:22 -0400 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1
Dude, which is more secure in your opinion. A base install of sendmail or a base install of OWA/exchange?
sorry, that was a bad comparison/joke. They are two different products. One is a mailserver, the other a webpage. To answer your question, leaving any SMTP server open to the web with only its base install is asking for trouble. A secure messaging infrastructure has layers just like any secure system. Firewall, SMTP Gateway, front end, then back end server is my preference, in that order, with the SMTP gateway being a different OS than your back end servers.
OWA is pretty nifty though, with almost every feature of the MAPI client. The only real fault I know about is the fact that you can guess passwords eternally without locking out user accounts. Also, as with any web front end, you can access it from anywhere. This means two things:
1: You cant control the security of the client machines. Whether it is a home PC, internet kiosk, or wifi connection at starbucks, the connection is going to be made from an infected machine sooner or later.
2: Using two factor authentication has to be done with SecureID, as most Kiosks and public use PC's dont have card readers.
If two factor authentication is not a possibility (due to cost or some such) then make sure to watch your logs for massive amounts of authentication attempts or even an unsusal amount of attempts for the same account.
-JP
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: [Full-disclosure] non-tech: defcon and FD. :), Morning Wood |
|---|---|
| Next by Date: | Re: [Full-disclosure] Secure OWA, Valdis . Kletnieks |
| Previous by Thread: | Re: [Full-disclosure] Secure OWA, Adriel Desautels |
| Next by Thread: | Re: [Full-disclosure] Secure OWA, Valdis . Kletnieks |
| Indexes: | [Date] [Thread] [Top] [All Lists] |