Need helping blocking telnet port 25

Status
Not open for further replies.

ZeroShade

In Runtime
Messages
498
Hi guys. Have a tough question, hopefully its easier for you guys. Basically I have an exchange server with smtp on port 25. Now, as you may be aware, users can take the external ip address of my network and telnet it specifying port 25 and gain access to mailing through telnet. This is bad! Very bad! Is there a way to block the tcp protocol of telnet on port 25 while still allowing SMTP to use port 25? Telnet is turned off but I'm under the impression this "test capability" is part of the SMTP package installed on the exchange server (and any other mailing service). Help please! Thanks!

~Marty
 
Not possible, you can block port 23 which is the default telnet port. if someone wants to hack your exchange server (assuming you are running 2007) they need to find what platform of exchange you are running and they will try that with telnet (assuming they know your domain name or ip) Exchange server 2007 no longer identifies the version of exchange being run which makes it more difficult for a hacker to get in, but then again if they really want to they will find out, unless its worth it i dont think no one would try to get into to your exchange server.

If your really worried here are some things you can do to guard against attacks. Im still in the process from learning exchange 2007 fully but from my knowledge you should not be worried, or you should be using smtps

* Physical access to the server Lock the doors and use some type of biotech authentication.
* Viruses, Trojans, and worms Use antivirus software and regularly scan your servers and workstations. Use the Exchange Server 2007 Edge Transport server role on at least one Exchange server.
* Loss of data Perform regular backups.
* Unauthorized use of user accounts Conduct user training on information security policies and require complex passwords.
* Denial of service attack Harden the TCP/IP stack and the router.
* Platform vulnerabilities Install all software patches and engage in service that offers minimization. Microsoft has released excellent free software for updating its patches on your servers. This software is called Windows Server Update Services (WSUS).
 
Status
Not open for further replies.
Back
Top Bottom