RE: fake sender and Exchange 5.5

From: Fullerton, James, CON, OASD(HA)/TMA (James.Fullerton@tma.osd.mil)
Date: 04/02/02


From: "Fullerton, James, CON, OASD(HA)/TMA" <James.Fullerton@tma.osd.mil>
To: "S.Leyers" <s.leyers@subdimension.com>, Focus MS List <focus-ms@securityfocus.com>
Date: Tue, 2 Apr 2002 12:44:51 -0500 

This page might have some articles that could assist you:

http://support.microsoft.com/default.aspx?scid=kb;EN-US;q196626

I found that by going to www.microsoft.com/exchange and then the quick link
for tips and tricks, which took me to:

http://www.microsoft.com/technet/treeview/default.asp?url=/TechNet/prodtechn
ol/exchange/tips/tips.asp

Hope that helps.

Thank you,

James Fullerton
James.Fullerton@tma.osd.mil
Web Site Developer
IntelliDyne, L.L.C.

-----Original Message-----
From: S.Leyers [mailto:s.leyers@subdimension.com]
Sent: Tuesday, April 02, 2002 7:53 AM
To: Focus MS List
Subject: fake sender and Exchange 5.5

Hi all,

--------------------------------------------------------------
Problem summary:
--------------------------------------------------------------
An external user can configure his POP3 mail client (outlook,outlook
express) with fake infos like:
Display name: "Big boss" from company @mydomain.org
Email: bigboss@mydomain.org
smtp server: smtp.userlocalisp.org

Now for a big joke or worse he sends a mail:

To: Main_distribution_list @mydomain.org
Subject: everybody get a salary raise !

Everybody will receive the mail as if it was the Boss itself who send the
mail. (You could only tell the thruth by checking the internet headers).

--------------------------------------------------------------
Environment overview in @mydomain.org:
--------------------------------------------------------------
    Firewall
        |
        |
SMTP relay
        |
        |
Exchange 5.5 sp4
       /|\
     / | \
W2K/NT4 clients

Relay & exchange are not openrelay.
Routing set to Reroute incoming SMTP mail....
Selected Routing Restrictions... Hosts and clients that successfully
authenticate and Hosts and clients with specific internal IP addresses

--------------------------------------------------------------
Goal to achieve:
--------------------------------------------------------------
Now as i can reproduce the case over and over, I would like to make the
necessary modifications so that it wouldn't happen anymore.

I would like to set a rule that says something like:
Check mail recipient field 'from' - If it contains "@mydomain.org" AND is
not from intern IP range -> Deny

I posted a request on MS newsgroup ... no usefull answer so far.
I couldn't find any information on how to achieve this.

Thanks for any help



Relevant Pages

  • Re: Reverse publish with isa2004?
    ... not all clients over the world. ... message retrieval, yet redirect all SMTP sends to your internal mail server, ... Are you using the same hostname for both SMTP and POP3? ... (the records in the "Internet" domain hosted at your provider). ...
    (microsoft.public.isaserver)
  • Re: SPAM from the inside.
    ... internal SMTP connectivity is blocked to all, allowed to few valid hosts that do require such connectivity - like non-Exchange mail hosts, scanners/copiers, et al. (The latter can be implemented if you have 2 SMTP virtual servers, or if inbound internet mail is received from particular SMTP hosts in your perimeter network or from a service provider). ...
    (microsoft.public.exchange.admin)
  • fake sender and Exchange 5.5
    ... smtp server: smtp.userlocalisp.org ... Everybody will receive the mail as if it was the Boss itself who send the ... (You could only tell the thruth by checking the internet headers). ... Hosts and clients that successfully ...
    (Focus-Microsoft)
  • Re: best distro for security
    ... when you've got two hosts behind the firewall. ... problems with it yet even though there were more clients. ... but every host could seperately access the internet. ...
    (comp.os.linux.security)
  • Certificates for SMTP service and web for Outlook 2007
    ... We have purchased a certificate, and I've gone into the "Assign Services to ... SMTP. ... in IIS, connections from the Internet are OK, but Outlook 2007 clients start ... noted on the Internet web clients. ...
    (microsoft.public.exchange.setup)