SMTP daemon supports EHLO |
---|
Risk Level: | Low | Check or Attack Name: EhloCheck |
---|---|---|
Platforms: | SMTP servers | |
Description: | SMTP daemons that support Extended HELO (EHLO) will release useful information to potential attackers. Attackers have been known to use the EHLO command to determine configuration information on SMTP daemons. |
|
Remedy: | Reconfigure your SMTP server to not support these extended features if you are not comfortable with the information they reveal. |
|
References: |
Know Your Risks |