SCO MMDF SMTP anti-relay disabled by default
| sco-openserver-mmdf-spam (4343) |
Description:
The default MMDF configuration in SCO UnixWare and SCO OpenServer allows SMTP message relaying. If the SMTP anti-relay feature is not enabled, malicious users can send spam email through your mail server, increasing the amount of traffic on the server.
Consequences:
Configuration
Remedy:
Disable mail relaying as described in the SCO Technical Article "How to configure MMDF to control mail routing on a per-host basis". See References.
References:
- Request for Comment document RFC 2505: Anti-Spam Recommendations for SMTP MTAs.
- SCO Security Web site: Security Fixes.
- SCO Technical Articles: How to configure MMDF to control mail routing on a per-host basis..
- CVE-1999-0512: A mail server is explicitly configured to allow SMTP mail relay, which allows abuse by spammers.
Platforms Affected:
- SCO SCO OpenServer 5.0
- SCO SCO OpenServer 5.0.4
- SCO SCO OpenServer 5.0.5
Reported:
Apr 20, 2000
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
