19.04.2013 Views

2KKUU7ita

2KKUU7ita

2KKUU7ita

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 13: Communication and Messaging Systems<br />

Finally, work with your marketing team and web developers to ensure that<br />

company e-mail addresses are not posted on the web. Also, educate your<br />

users about not doing this.<br />

Relay<br />

SMTP relay lets users send e-mails through external servers. Open e-mail<br />

relays aren’t the problem they used to be, but you still need to check for<br />

them. Spammers and hackers can use an e-mail server to send spam or malware<br />

through e-mail under the guise of the unsuspecting open-relay owner.<br />

Be sure to test for open relay from outside your network. If you test from<br />

inside, you might get a false positive because outbound e-mail relaying might<br />

be configured and necessary for your internal e-mail clients to send messages<br />

to the outside world. However, if a client system is compromised, that<br />

issue could be just what the bad guys need to launch a spamming or malware<br />

attack.<br />

Automatic testing<br />

Here are a couple of easy ways to test your server for SMTP relay:<br />

✓ Free online tools: One of my favorite online tools is located at www.<br />

abuse.net/relay.html.<br />

✓ Windows-based tools: One example is NetScanTools Pro (www.<br />

netscantools.com). You can run an SMTP Relay check on your e-mail<br />

server with NetScanTools Pro, as shown in Figure 13-9.<br />

Although some SMTP servers accept inbound relay connections and<br />

make it look like relaying works, this isn’t always the case because the<br />

initial connection might be allowed, but the filtering actually takes place<br />

behind the scenes. Check whether the e-mail actually made it through<br />

by checking the account you sent the test relay message to.<br />

In NetScanTools Pro, you simply enter values for the SMTP mail server<br />

name, Your Sending Domain Name. Inside Test Message Settings, enter the<br />

Recipient Email Address and Sender’s Email Address.<br />

When the test is complete, simply click View Relay Test Results. Depending<br />

on which option you’ve selected, you’ll see the results of your tests, as<br />

shown in Figure 13-10.<br />

261

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!