Re: Exchange/MAPI/RPC

From: Simara (simara@formdesign.com)
Date: 03/13/03

  • Next message: Laura A. Robinson: "RE: AD replication - IP site to site encryption?"
    From: "Simara" <simara@formdesign.com>
    To: <focus-ms@securityfocus.com>
    Date: Thu, 13 Mar 2003 05:17:28 -0500
    
    

    It is not recommend to publish any RPC interface on Windows Servers, there
    are tons of exploits that could be executed, and besides, the kind of RPC
    outlook uses is really heavy on the network, so I wont recommend it, use a
    VPN.

    On the other side of the story, the new Exchange Server and Office suite,
    both due in about 3 months, will bring a new solution: Http-RPC, using the
    standard Web Access as a connection for the Outlook 2003, and it is secure,
    no RPC ports open, and I already teste it and its sweet (really fast), the
    HTTP RPC is nota full RPC publishing, just what you need.

    Tested on both beta 2 version of each product.

    Alex
    ----- Original Message -----
    From: "Willis Johnson" <willisj@microsoft.com>
    To: <focus-ms@securityfocus.com>
    Sent: Tuesday, March 11, 2003 4:17 PM
    Subject: RE: Exchange/MAPI/RPC

    There's a case study describing how Microsoft secures remote users at
    this website:
    http://www.microsoft.com/technet/treeview/default.asp?url=/technet/itsol
    utions/msit/security/srutcase.asp

    Willis Johnson
    Microsoft

    ----------------------------------------------------------------------
    ALERT: How a Hacker Uses SQL Injection to Steal Your SQL Data!
    It's as simple as placing additional SQL commands into a Web Form input
    box giving hackers complete access to all your backend systems!
    http://www.spidynamics.com/mktg/sqlinjection33


  • Next message: Laura A. Robinson: "RE: AD replication - IP site to site encryption?"

    Relevant Pages

    • Re: RPC over HTTP not working from external clients
      ... I would recommend the following links ... > When connecting to email via RPC over HTTP internally, ... > everything works fine but when tying to connect from ...
      (microsoft.public.exchange.admin)
    • Re: LOOKSystems
      ... please could someone recommend ... both for the Iyonix and RPC? ... Actually, Atlanta seems to work perfectly well, and it's PD ...
      (comp.sys.acorn.apps)
    • Re: RPC over HTTP
      ... RPC over HTTPS is the recommend way of doing this. ... Not sure why he would put a note in the article for not doing this other than for testing/lab environment or you already have VPN connectivity requirements for your external users but then why use RPC over HTTP anyways. ... While RPC over HTTP does not require SSL, ...
      (microsoft.public.exchange.misc)
    • Transactional Replication with Updating Subscribers and RPC
      ... I have a real sticky problem that I hope one of you bright SQL gods can help ... Problem is, my understanding is in order to use this replication, ... RPC traffic has to be allowed across the firewalls of the networks. ... Furthermore these transactions may be ...
      (microsoft.public.sqlserver.replication)
    • Re: Transactional Replication with Updating Subscribers and RPC
      ... The rpc calls are made over port 1433 or whatever port you are using for SQL ... The only replication type which uses MSDTC is immediate updating. ... Looking for a SQL Server replication book? ...
      (microsoft.public.sqlserver.replication)