RE: Exchange/MAPI/RPC

From: Campbell, Ian C (ian.c.campbell@eds.com)
Date: 03/10/03

  • Next message: Bob the Builder: "Re: DisableIPSourceRouting registry key"
    From: "Campbell, Ian C" <ian.c.campbell@eds.com>
    To: "'Joseph Burton'" <joseph_burton1970@hotmail.com>
    Date: Mon, 10 Mar 2003 16:10:44 -0500
    
    

    Regardless of the security implications of opening MAPI/RPC to a public
    network, you should not do this. You will never know all the exploits
    available.

    The most convincing argument in my mind is simply: if you don't need the
    general public accessing a particular service, don't make a connection to
    that service available to the general public. Use a VPN to control who can
    connect to the service in the first place.

    -----Original Message-----
    From: Joseph Burton [mailto:joseph_burton1970@hotmail.com]
    Sent: March 8, 2003 11:08 AM
    To: focus-ms@securityfocus.com
    Subject: Exchange/MAPI/RPC

    Hello all,

    I have a client that will soon start using Microsoft Exchange, and I have a
    question regarding the Outlook client. The Exchange client in Outlook uses
    the MAPI protocol which uses RPC to communicate with the Exchange server. I
    know it's not recommended to connect from the Internet using MAPI, without
    using any form av encryption like IPSec.

    My question is simply, why? Why is it dangerous to use MAPI/RPC over
    Internet? Is the password sent in clear text or something? I need some good
    arguments to convince my client to use VPN for the roaming users.

    Thanks in advance,

    //Joe

    _________________________________________________________________
    Skaffa fler messengerkontakter - Vinn 10.000 i resecheckar!
    http://messenger.msn.se/promo


  • Next message: Bob the Builder: "Re: DisableIPSourceRouting registry key"

    Relevant Pages

    • Re: Cannot login to retrieve internet mail
      ... You are correct in that when I connect with one of these accounts (that do ... not work) from an outlook client I am attemting to receive mail. ... > POP client - only the Exchange server for POP, ... > Internet - this is entirely different. ...
      (microsoft.public.exchange.admin)
    • Re: Client refusing incoming smtp messages
      ... Then don't mention the client & SMTP server. ... Is moxa.com your registered Internet domain? ... exchange server or anything else at that matter. ...
      (microsoft.public.exchange.clients)
    • Re: Internal vs External Domains
      ... > I am planning an Windows 2003 Active Directory domain for a client ... > registered and has an active website on the Internet. ... > 4) What other Exchange issues should I be concerned about? ... Microsoft Windows MVP - Active Directory ...
      (microsoft.public.win2000.dns)
    • Re: change domain name advice?
      ... Internet domain name. ... I have an ongoing issue where the Outlook client can send to another ... choose which Inbox to forward to, the POP or the Exchange. ... The Entourage user must drag the appt. ...
      (microsoft.public.exchange.admin)
    • Re: Certain rules not working
      ... Internet Message Format ... Exchange - System-Manager ... I had failed to allow message forwarding on the server side. ... A client is having issues with setting server-based rules onto Exchange 2003 ...
      (microsoft.public.windows.server.sbs)

  • Quantcast