Re: Discovering users by RCPT TO

From: Vince Hoang (vince_at_litrium.com)
Date: 01/14/05

  • Next message: Nazareno Vicente Feito: "Re: DoS/DDoS Attack"
    Date: Thu, 13 Jan 2005 13:20:15 -1000
    To: pen-test@securityfocus.com
    
    

    On Thu, Jan 13, 2005 at 02:20:12PM -0500, Chris Buechler wrote:
    > I'd recommend disabling it unless you get flooded by such spam
    > attacks. I would probably consider it unnecessary information
    > disclosure, depending on the environment and reason (if any)
    > for doing it that way.

    Some MTAs allow permit you to drop the session after a certain
    number of failures, but that only slows down the dictionary
    attacks.

    You cannot disable RCPT TO because that is how the SMTP protocol
    designates the recipients.

    -Vince


  • Next message: Nazareno Vicente Feito: "Re: DoS/DDoS Attack"

    Relevant Pages

    • RE: Discovering users by RCPT TO
      ... MimeSweeper are both anti-spam vendors that do this that I can think of ... > I'd recommend disabling it unless you get flooded by such spam ... > attacks. ... You cannot disable RCPT TO because that is how the SMTP protocol ...
      (Pen-Test)
    • Re: [Lit.] Buffer overruns
      ... programming language can be influenced by the operational environment. ... there were a couple of denial of service attacks that were quickly ... when dealing with single disk testcell (although it normally ran fine ...
      (sci.crypt)
    • Re: Deep Freeze
      ... environment and it offers some unique capabilities. ... Audit your website security with Acunetix Web Vulnerability Scanner: ... Cross site scripting and other web attacks before hackers do! ...
      (Pen-Test)
    • Re: Writing Secure code
      ... or physical attacks is true and obvious, but is not really germane to ... > attainable total security (e.g., ... >> and wrote were stored on a remote file system such as an SMB mount, ... > environment, but it's something of a desireable side effect of good ...
      (SecProg)
    • RE: Active Directory user enumeration
      ... > environment and I could not find a way to anonymously ... Audit your website security with Acunetix Web Vulnerability Scanner: ... Cross site scripting and other web attacks before hackers do! ...
      (Pen-Test)