Re: email authentication

phn_at_icke-reklam.ipsec.nu
Date: 10/27/04


Date: Wed, 27 Oct 2004 06:50:57 +0000 (UTC)

willy gates <willy_gates@hotmail.com> wrote:
> Hello

> BT have asked us to enable SMTP email authentication, good idea I
> thought...

> But then I began to think...

> I am logging into BT SMTP or POP3 server and sending them a login and
> a password. I have not got a secure connection SSL, nor is secure
> authentication supported. Therefore I assume that I am sending a
> plaintext username and password each time I log into the BT server to
> send/receive my email.

> Is this correct?

Yes.

> That means if I get a virus that wants to set up a spam zombie on my
> machine sending spam to my BT server then BT have prevented them from
> sending unauthenticated spam however it wouldn't take much to read my
> unauthenticated password and start using my BT login to send spam.
Correct. Thats why sender-id won't stop spam.

 Or
> do the spam zombies created by these virus send their email using
> other servers?
They could. But it easier to use your configured MTA

> Thanks for your help

-- 
Peter Håkanson         
        IPSec  Sverige      ( At Gothenburg Riverside )
           Sorry about my e-mail address, but i'm trying to keep spam out,
	   remove "icke-reklam" if you feel for mailing me. Thanx.


Relevant Pages

  • Re: How to do rDNS. WAS: RE: educating rDNS violators
    ... It's done in the DNS server. ... As a spam prevention measure, a lot of end-user Internet providers are ... Using your own mail server as a slave to the ISP's mail server will add ...
    (Security-Basics)
  • RE: OMA and Outgoing Spam
    ... Someone hacked a user account and use it to spam emails; ... Your Exchange server is open relaying emails;(You have checked it ... Your server is under RNDR Attack. ... Microsoft is providing this information as a convenience to you. ...
    (microsoft.public.windows.server.sbs)
  • RE: OMA and Outgoing Spam
    ... Someone hacked a user account and use it to spam emails; ... Your Exchange server is open relaying emails;(You have checked it ... Your server is under RNDR Attack. ... When you enable recipient filtering on the SMTP virtual server, ...
    (microsoft.public.windows.server.sbs)
  • Re: Anyone succesfully stopped Reverse NDR Attacks in exchange 2000?
    ... to their filtering servers and the Spam stops filling your Exchange Queues ... and destined to an non existing address on your server. ... connecting addresses as there are spam sent. ...
    (microsoft.public.exchange2000.admin)
  • Re: educating rDNS violators
    ... Our previous mail server setup included refusing all messages coming from ... Another way to catch a fair amount of spam is to require that the "From:" ... MX records to the filter then the filter would forward mail to our SMTP ...
    (Security-Basics)