Hi Guys,
We recently had an external penetration test and one of the issues raised was the fact that anyone can telnet into our SMTP gateway and send forged emails from ANY email address to any user in our domain. I have my doubts as to whether this is a legitimate issue so would like to ask the community:
- Is this a security risk?
- Is this correct and/or the default behaviour?
- How can i prevent this?
Thanks and Regards,
Samuel
Bookmarks