Sendmail %style blind relaying can be used to obfuscate the origin of e-mails

Risk Level: Medium risk vulnerability  Medium

Check or Attack Name: smtprelay

Platforms: Sendmail
Description:

An SMTP server supports third-party or %style mail relaying. Third-party mail relaying occurs when a mail server processes a mail message where neither the sender nor the recipient is local to the server's mail domain.

While third party relaying has some legitimate purposes, such as allowing mail messages to be routed around known mail problems, e-mail hijackers (or spammers) primarily use it to obscure their identity while sending large amounts of junk mail.

Remedy:

Re-configure your SMTP server to enforce that all mail messages must either originate or terminate locally (on the mail host).

References:

Sendmail Consortium, Anti-Spam Provisions in Sendmail 8.8, http://www.sendmail.org/antispam.html

Mail Abuse Protection System (MAPS), , http://maps.vix.com

Fight Spam on the Internet!, , http://spam.abuse.net/

, Anti-Relay: Stop Third-Party Mail Relay, http://maps.vix.com/tsi/ar-fix.html


X-Force Logo
Know Your Risks