Telnet SMTP problem

Soldato
Joined
8 Mar 2003
Posts
2,857
Location
Washington
A friend just asked me this:

The server is busy grinding to a hault at the minute. I have a funny feeling someone is using us as a spam relay server (bandwidth is through the roof). Now I've stopped the Telnet service but I can still Telnet to port 25 and send mail (spoof mail from whoever I like).

Any ideas how I stop anyone being able to Telnet through the SMTP port (bear in mind we need SMTP to be running for our mail)

He's running 2003 SBS, i've racked my brains but couldn't come up with much.
 
He needs to get a clue for a start.

They're not using "telnet through the SMTP port", they're just running an SMTP session. It's coincidence more than anything that you can use telnet as a client. All it (and the human behind it) are doing is what your mail client's doing in the background.
The only way you'd stop folks using telnet to connect the SMTP server would be to stop the SMTP server altogether, or block it from the internet.

He'd be much better placed trying to stop his mail server working as an open relay before it gets blocked, than doing anything else. Requiring SMTP authentication would be one suggestion.
 
You either need to filter it to specific IP addresses or have some kind of SMTP Authentication, another way is to make it so when you "POP" the server which requires a username/password, it allows your IP address to send through the server for say 3 minutes.

But you better sort it out ASAP, your IP address has probably already been added to every blacklist going. :D
 
Back
Top Bottom