The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Cpanel's exim a security hole according to nessusd

Discussion in 'Security' started by BianchiDude, Jul 26, 2009.

  1. BianchiDude

    BianchiDude Well-Known Member
    PartnerNOC

    Joined:
    Jul 2, 2005
    Messages:
    619
    Likes Received:
    0
    Trophy Points:
    16
    I ran a scan on my cpanel server with nessusd and its saying exim is a security hole:
    results|com|mydomain.com|smtp (25/tcp)|11852|Security Hole|\nSynopsis :\n\nAn open SMTP relay is running on this port.\n\nDescription :\n\nThe remote SMTP server is insufficiently protected against relaying. \nThis means that it allows spammers to use your mail server to send \ntheir mails to the world, thus wasting your network bandwidth.\n\nSolution :\n\nReconfigure your SMTP server so that it cannot be used as a relay \nany more.\n\nRisk factor :\n\nHigh / CVSS Base Score : 7.8\n(CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C)\n\nPlugin output :\n\nNessus was able to relay mails by sending those sequences :\n\n MAIL FROM: <nessus@mydomain.com>\n RCPT TO: <nobody%example.com@mydomain.com>\n\n

    How can I fix this?

    TIA
     
  2. cPanelDavidG

    cPanelDavidG Technical Product Specialist

    Joined:
    Nov 29, 2006
    Messages:
    11,279
    Likes Received:
    8
    Trophy Points:
    38
    Location:
    Houston, TX
    cPanel Access Level:
    Root Administrator
    cPanel/WHM does not set up an open relay. However, POP before SMTP authentication will trigger scanners into thinking you have an open relay. POP before SMTP authentication is enabled by default and allows anyone who has successfully authenticated via POP3 within the past 30 minutes to send outbound mail via your server.

    This is different from an open relay where server authentication is not required at all.

    If you want to force SMTP authentication for all outbound mail (effectively disabling POP before SMTP authentication), go to WHM -> Service Configuration -> Service Manager and uncheck "Antirelayd" (under TailwatchD). Then click "save" at the bottom of the page.
     
  3. BianchiDude

    BianchiDude Well-Known Member
    PartnerNOC

    Joined:
    Jul 2, 2005
    Messages:
    619
    Likes Received:
    0
    Trophy Points:
    16
    Thank you for clarifying this.
     
Loading...

Share This Page