RE: POP3

From: Gary McKinney (gmckinney@megabits.net)
Date: 03/02/02


From: "Gary McKinney" <gmckinney@megabits.net>
To: "Burleson, Lee (IA)" <Lee.Burleson@ia.ngb.army.mil>, <shady@netway.at>, <security-basics@securityfocus.com>
Date: Sat, 2 Mar 2002 09:46:48 -0500

Lee - there is one "caveat" to what you have stated...

The "question" was what were the security implications of allowing users to
use POP3 to access external email servers (not the exchange server and you
are correct about POP3 to the exchange server)...

The external email servers should have a different username and password
than the internal exchange server to start with - if the external email
server supports encrypted (secure POP3) then all the better...

personally I would have the external email server forward the email to the
user through the exchange server and NOT give them POP-3 access to an
outside email server... The reason for this is two-fold:

1. You can setup filters on the firewall and install third-party virus
scanners on the exchange server to "trap" malicious attachments on the email
and....

2. Control the use of the email system for business purposes only....

The first one is really the main one!!! Most of the email virus and Trojan
attachments getting through to company systems has entered through external
POP-3 accounts on internal workstations... Even if you filter at the
workstation with virus scanners you may miss some of them (especially the
new ones that have not been picked out of the wild and have virus signatures
or the workstation is not totally up to date on the signature file). By
having the external email routed to the exchange server you can setup
third-party filters and virus scanners to "trap" by attachment and content
to stop the virus code before it can do damage...

Just some thoughts...

gm...

> -----Original Message-----
> From: Burleson, Lee (IA) [mailto:Lee.Burleson@ia.ngb.army.mil]
> Sent: Wednesday, February 27, 2002 11:18 PM
> To: 'shady@netway.at'; 'security-basics@securityfocus.com'
> Subject: RE: POP3
>
>
> Take the following into consideration...
>
> Given:
> * POP3 authentication is clear text
> * MS Exchange authenticates against NT/2000 user accounts
>
> Therefore:
> * The POP3 username & password are the same credentials used to
> access network resources.
> * Compromised POP3 credentials will also compromise the entire
> domain.
>
> Conclusion: POP3 is a bad idea, even in a LAN.
>
> - Lee
>
>
> -----Original Message-----
> From: shady@netway.at [mailto:shady@netway.at]
> Sent: Saturday, February 23, 2002 4:00 PM
> To: security-basics@securityfocus.com
> Subject: POP3
>
>
>
>
> My users want me to to give them POP3 access via
> the firewall. We have an Exchange Server runnig with
> a Checkpoint Firewall. Are there any security issues
> that I need to watch out



Relevant Pages

  • Re: External emails being collected but not distributed
    ... >removed it, I have not recieved an external email since, Out going no problem ... >reports collecting them, and my ISP can see them being collected by my ... >I am wondering weather the POP3 Collector is not passing the emails on to ... The POP3 server on your Exchange server has got nothing to do with it. ...
    (microsoft.public.exchange.admin)
  • Re: Exchange PLUS POP3
    ... configuring the POP3 Locally. ... it shows blocked by the SBS Internet Users rule. ... their mail servers so if our Exchange server goes down we can log onto ... Outlook pointing to the ISP POP and SMTP servers and all he has to do ...
    (microsoft.public.windows.server.sbs)
  • Re: SBS Remote Access to email
    ... POP3 email from Exchange server. ... This newsgroup only focuses on SBS technical issues. ... you may want to contact Microsoft CSS directly. ...
    (microsoft.public.windows.server.sbs)
  • RE: Exchange Problem
    ... Use the telnet tool to connect the exchange server. ... Troubleshooting POP3 Connections to Exchange Server ... Open Outlook Express. ... This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)
  • Re: Vanishing email
    ... I wonder if it wouldn't be easier to just let Outlook POP the mail from the ISP; especially since you're only talking about a handful of users. ... Therefore the pop3 choice ... on the exchange server and skip the pop3" you mentioned? ... email and direct it to the account. ...
    (microsoft.public.windows.server.sbs)

Loading