Re: Exchange/MAPI/RPC

From: jmcguire@sbcs.com
Date: 03/10/03

  • Next message: Jens Mickerts: "AW: Exchange/MAPI/RPC"
    To: "Joseph Burton" <joseph_burton1970@hotmail.com>
    From: jmcguire@sbcs.com
    Date: Mon, 10 Mar 2003 15:04:59 -0500
    
    

    To implement this, you need to open netbios port 135 to the Internet as
    well as a pipe into your Exchange directory and information stores. With
    Exchange 2000 this is actually 3 ports that must be locked down in the
    registry of the Exchange server. Netbios is very vulnerable when exposed to
    the big bad world. The other services are pretty much untested and
    therefore suspect. I've personally been able to hold customers off on this.
    The one that wants it is a juicy terrorist target though so they kind of go
    along with my security recommendations and suffer through a VPN
    authentication first.

    An MS contact on another list says ISA server feature pack 1 is supposed to
    allow this securely, but who uses ISA, and besides, this new version has
    also not been tested yet. Found a link on microsoft.com
    http://www.microsoft.com/isaserver/featurepack1/email.asp

    Good Luck!

    __________________________________________
    JOHN MCGUIRE CISSP, MCSE2k, MCSE+I
    Network Security Specialist
    888.529.0401
    jmcguire@sbcs.com
    Strictly Business
    www.sbcs.com

                                                                                                                                              
                          "Joseph Burton"
                          <joseph_burton1970@h To: focus-ms@securityfocus.com
                          otmail.com> cc:
                                                      Subject: Exchange/MAPI/RPC
                          03/08/2003 11:07 AM
                                                                                                                                              
                                                                                                                                              

    Hello all,

    I have a client that will soon start using Microsoft Exchange, and I have a

    question regarding the Outlook client. The Exchange client in Outlook uses
    the MAPI protocol which uses RPC to communicate with the Exchange server. I

    know it's not recommended to connect from the Internet using MAPI, without
    using any form av encryption like IPSec.

    My question is simply, why? Why is it dangerous to use MAPI/RPC over
    Internet? Is the password sent in clear text or something? I need some good

    arguments to convince my client to use VPN for the roaming users.

    Thanks in advance,

    //Joe

    _________________________________________________________________
    Skaffa fler messengerkontakter - Vinn 10.000 i resecheckar!
    http://messenger.msn.se/promo


  • Next message: Jens Mickerts: "AW: Exchange/MAPI/RPC"

    Relevant Pages

    • Re: Cannot login to retrieve internet mail
      ... You are correct in that when I connect with one of these accounts (that do ... not work) from an outlook client I am attemting to receive mail. ... > POP client - only the Exchange server for POP, ... > Internet - this is entirely different. ...
      (microsoft.public.exchange.admin)
    • Re: Client refusing incoming smtp messages
      ... Then don't mention the client & SMTP server. ... Is moxa.com your registered Internet domain? ... exchange server or anything else at that matter. ...
      (microsoft.public.exchange.clients)
    • RE: Cant send or receive e-mail to POP3 users on same domain--HELP!
      ... Run the CEICW and go through the Internet and firewall option. ... If you choose to forward emails to the ISP's email server (smart ... Connector for POP3 Mailboxes' option, ... The Mailbox type is User Mailbox, and select the appropriate Exchange ...
      (microsoft.public.windows.server.sbs)
    • Re: Internal vs External Domains
      ... > I am planning an Windows 2003 Active Directory domain for a client ... > registered and has an active website on the Internet. ... > 4) What other Exchange issues should I be concerned about? ... Microsoft Windows MVP - Active Directory ...
      (microsoft.public.win2000.dns)
    • Re: Certain rules not working
      ... Internet Message Format ... Exchange - System-Manager ... I had failed to allow message forwarding on the server side. ... A client is having issues with setting server-based rules onto Exchange 2003 ...
      (microsoft.public.windows.server.sbs)

  • Quantcast