Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 3 of 3
  1. #1
    Member mickalo's Avatar
    Join Date
    Apr 2002
    Location
    N.W. Iowa
    Posts
    753

    Default PCI Compliance

    Hello,

    Ok, this one has me stumped. We have a customer with 3 domains on our server. 2 of them passed this Security Metrics PCI scan, but one did not and for the life of me can't figure why. 2 of them passed so I assume that the Exim global configuration is setup correctly and the one that failed may have something to do with the DNS zone file .... not sure ?? This is the results they go back:
    Code:
    Protocol Port Program Risk Summary
    
    TCP 25 smtp 4 The remote SMTP server is insufficiently protected against relaying 
    This means that spammers might be able to use your mail server to send their mails to the world. 
    SMetrics was able to relay mails by sending those sequences: 
    MAIL FROM: <smetrics@decisionbar.com> 
    RCPT TO: <nobody%securitymetrics.com@decisionbar.c om> Risk Factor: Medium 
    
    TCP 465 urd 4 The remote SMTP server is insufficiently protected against relaying 
    This means that spammers might be able to use your mail server to send their mails to the world. 
    SMetrics was able to relay mails by sending those sequences: 
    MAIL FROM: <smetrics@decisionbar.com> 
    RCPT TO: <nobody%securitymetrics.com@decisionbar.c om> Risk Factor: Medium Solution: 
    upgrade your software or improve the configuration so that your SMTP server cannot be used 
    as a relay any more.
    any suggestion or help would be much appreciated. I've been racking my brain all morning trying
    to figure this out.

    Thx's
    Mike

    Thunder Rain Internet Publishing

    Providing Internet Solutions that work!
    Custom Perl and Database Programming

  2. #2
    Technical Product Specialist cPanelDavidG's Avatar
    Join Date
    Nov 2006
    Location
    Houston, TX
    Posts
    11,189
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Quote Originally Posted by mickalo View Post
    Hello,

    Ok, this one has me stumped. We have a customer with 3 domains on our server. 2 of them passed this Security Metrics PCI scan, but one did not and for the life of me can't figure why. 2 of them passed so I assume that the Exim global configuration is setup correctly and the one that failed may have something to do with the DNS zone file .... not sure ?? This is the results they go back:
    Code:
    Protocol Port Program Risk Summary
    
    TCP 25 smtp 4 The remote SMTP server is insufficiently protected against relaying 
    This means that spammers might be able to use your mail server to send their mails to the world. 
    SMetrics was able to relay mails by sending those sequences: 
    MAIL FROM: <smetrics@decisionbar.com> 
    RCPT TO: <nobody%securitymetrics.com@decisionbar.c om> Risk Factor: Medium 
    
    TCP 465 urd 4 The remote SMTP server is insufficiently protected against relaying 
    This means that spammers might be able to use your mail server to send their mails to the world. 
    SMetrics was able to relay mails by sending those sequences: 
    MAIL FROM: <smetrics@decisionbar.com> 
    RCPT TO: <nobody%securitymetrics.com@decisionbar.c om> Risk Factor: Medium Solution: 
    upgrade your software or improve the configuration so that your SMTP server cannot be used 
    as a relay any more.
    any suggestion or help would be much appreciated. I've been racking my brain all morning trying
    to figure this out.

    Thx's
    Mike
    Looks like this PCI Compliance Vendor doesn't understand the difference between open relays and cPanel/WHM's POP-before-SMTP authentication.

    In a cPanel/WHM environment, if you have successfully authenticated into POP within the past 30 minutes, then you (or more technically, your IP address) can send mail via the SMTP server without authentication (since you have already authenticated successfully via POP).

    To disable this POP-before-SMTP authentication and force SMTP authentication for all users at all times, go to WHM -> Service Configuration -> Service Manager and under tailwatchd, uncheck "Antirelayd."

  3. #3
    Member mickalo's Avatar
    Join Date
    Apr 2002
    Location
    N.W. Iowa
    Posts
    753

    Default

    Thanks. After reading your reply it makes allot of sense. We have several of these scans in the past with other customers and never got this type of warning before. So I was a bit lost to what the problems was.

    Mike

    Thunder Rain Internet Publishing

    Providing Internet Solutions that work!
    Custom Perl and Database Programming

Similar Threads & Tags
Similar threads

  1. PCI Compliance
    By richardsonchris in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 03-21-2011, 08:04 AM
  2. PCI Compliance
    By mickalo in forum Security
    Replies: 3
    Last Post: 12-15-2009, 12:41 PM
  3. PCI Compliance
    By FourMat in forum cPanel and WHM Discussions
    Replies: 10
    Last Post: 02-19-2009, 10:09 AM
  4. pci compliance help
    By EWD in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 05-29-2008, 11:34 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube