SMTP daemon supports EHLO |
---|
Risk Level: | ![]() |
Check or Attack Name: EhloCheck |
---|---|---|
Platforms: | SMTP servers | |
Description: | SMTP daemons that support Extended HELO (EHLO) will release useful information to potential attackers. Attackers have been known to use the EHLO command to determine configuration information on SMTP daemons. |
|
Remedy: | Reconfigure your SMTP server to not support these extended features if you are not comfortable with the information they reveal. |
|
References: |
![]() Know Your Risks |