Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Security-Basics
[Top] [All Lists]

Re: ESMTP service

Subject: Re: ESMTP service
Date: Tue, 25 Dec 2007 01:41:09 +0100
On 2007-12-24 sisram2@gmail.com wrote:
I'm looking for info on exploits and security of ESMTP when you telnet
into port 25. I understand how to telnet in and send email via the
command line but trying to understand the security implications of
being able to do this. I am currently looking at this on Exchange 5.5.

Does ESMTP from the command line need to be "accessible" for the apps
to work or enabled to troubleshoot?

Are their DDOS attacks or hacks against ESMTP?

Is there a best practice to secure ESMTP

I've been able find info about ESMTP (commands) but not much info on
the potential security risks.

http://www.faqs.org/rfcs/rfc2821.html

Regards
Ansgar Wiechers
-- 
"All vulnerabilities deserve a public fear period prior to patches
becoming available."
--Jason Coombs on Bugtraq

<Prev in Thread] Current Thread [Next in Thread>