Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 3 of 3
  1. #1
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Jul 2005
    Posts
    609

    Default Cpanel's exim a security hole according to nessusd

    I ran a scan on my cpanel server with nessusd and its saying exim is a security hole:
    results|com|mydomain.com|smtp (25/tcp)|11852|Security Hole|\nSynopsis :\n\nAn open SMTP relay is running on this port.\n\nDescription :\n\nThe remote SMTP server is insufficiently protected against relaying. \nThis means that it allows spammers to use your mail server to send \ntheir mails to the world, thus wasting your network bandwidth.\n\nSolution :\n\nReconfigure your SMTP server so that it cannot be used as a relay \nany more.\n\nRisk factor :\n\nHigh / CVSS Base Score : 7.8\n(CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C)\n\nPlugin output :\n\nNessus was able to relay mails by sending those sequences :\n\n MAIL FROM: <nessus@mydomain.com>\n RCPT TO: <nobody%example.com@mydomain.com>\n\n

    How can I fix this?

    TIA

  2. #2
    Technical Product Specialist cPanelDavidG's Avatar
    Join Date
    Nov 2006
    Location
    Houston, TX
    Posts
    11,189
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Quote Originally Posted by BianchiDude View Post
    I ran a scan on my cpanel server with nessusd and its saying exim is a security hole:
    results|com|mydomain.com|smtp (25/tcp)|11852|Security Hole|\nSynopsis :\n\nAn open SMTP relay is running on this port.\n\nDescription :\n\nThe remote SMTP server is insufficiently protected against relaying. \nThis means that it allows spammers to use your mail server to send \ntheir mails to the world, thus wasting your network bandwidth.\n\nSolution :\n\nReconfigure your SMTP server so that it cannot be used as a relay \nany more.\n\nRisk factor :\n\nHigh / CVSS Base Score : 7.8\n(CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C)\n\nPlugin output :\n\nNessus was able to relay mails by sending those sequences :\n\n MAIL FROM: <nessus@mydomain.com>\n RCPT TO: <nobody%example.com@mydomain.com>\n\n

    How can I fix this?

    TIA
    cPanel/WHM does not set up an open relay. However, POP before SMTP authentication will trigger scanners into thinking you have an open relay. POP before SMTP authentication is enabled by default and allows anyone who has successfully authenticated via POP3 within the past 30 minutes to send outbound mail via your server.

    This is different from an open relay where server authentication is not required at all.

    If you want to force SMTP authentication for all outbound mail (effectively disabling POP before SMTP authentication), go to WHM -> Service Configuration -> Service Manager and uncheck "Antirelayd" (under TailwatchD). Then click "save" at the bottom of the page.

  3. #3
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Jul 2005
    Posts
    609

    Default

    Thank you for clarifying this.

Similar Threads & Tags
Similar threads

  1. Replies: 109
    Last Post: 06-22-2004, 07:39 PM
  2. the cpanel security hole thing
    By Getox in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 06-08-2004, 09:48 AM
  3. Exim security hole and lack of FreeBSD updates???
    By Jeff75 in forum cPanel and WHM Discussions
    Replies: 7
    Last Post: 06-01-2004, 12:46 PM
  4. exim security hole!!
    By sodapopinski in forum cPanel and WHM Discussions
    Replies: 117
    Last Post: 05-18-2004, 09:57 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube