SMTP server allows fake hostnames in HELO |
---|
Risk Level: | Low | Check or Attack Name: SMTPforgery |
---|---|---|
Platforms: | Any, Sendmail | |
Description: | The SMTP server was found to accept any hostname issued to it in the HELO command. This lack of authorization could allow users to more easily forge mail from your server. |
|
Remedy: | Upgrade your Mail Transfer Agent (MTA) to a package or version that supports more rigorous validation of hostnames. It may be possible to configure your server to do this; refer to your server's documentation. |
|
References: |
Know Your Risks |