pen-test
[Top] [All Lists]

RE: publications concerning port forwarding

To: <pen-test@securityfocus.com>
Subject: RE: publications concerning port forwarding
From: "Wiedemann, Adrian" <Adrian.Wiedemann@rz.uni-karlsruhe.de>
Date: Wed, 11 Apr 2007 19:50:43 +0200
Delivered-to: sp-com-lists@consult.net
Delivered-to: pentest-list2@consult.net
Delivered-to: mailing list pen-test@securityfocus.com
Delivered-to: moderator for pen-test@securityfocus.com
In-reply-to: <Pine.LNX.4.58.0704111047230.6970@shell.datasync.com>
List-help: <mailto:pen-test-help@securityfocus.com>
List-id: <pen-test.list-id.securityfocus.com>
List-post: <mailto:pen-test@securityfocus.com>
List-subscribe: <mailto:pen-test-subscribe@securityfocus.com>
List-unsubscribe: <mailto:pen-test-unsubscribe@securityfocus.com>
Mailing-list: contact pen-test-help@securityfocus.com; run by ezmlm
References: <Pine.LNX.4.58.0704101707530.6970@shell.datasync.com> <5A71427437E8E8459E356079FEAC7D430304E226@rzms-ex1.rz.uni-karlsruhe.de> <Pine.LNX.4.58.0704111047230.6970@shell.datasync.com>
Resent-date: Wed, 11 Apr 2007 11:51:38 -0600 (MDT)
Resent-from: pen-test-return-1078483921@securityfocus.com
Resent-message-id: <20070411175138.A4CDE144B46@outgoing2.securityfocus.com>
Resent-sender: listbounce@securityfocus.com
Sender: listbounce@securityfocus.com
Thread-index: Acd8VEWvSHxM+CbuTimxsybEp7bx5QACs7cg
Thread-topic: publications concerning port forwarding
Hi,

>   My concern would be a 0-day exploit for the service that is exposed.> An
> internal MS Exchange server responding to public internet traffic,
> seems
> less secure than say... a postfix server in the DMZ and a MS Exchange
> server on the internal network.at least in this situation you would
> need
> two services to be exploitable (Postfix SMTP and MS Exchange) rather
> than
> just MS Exchange.

Ok, two things. First, Preventing against a 0day is always hard - regardless
of the system. Second, what do you define as internal? Is the MS Exchange is
only used internally  (no RPC-over-HTTPS, no OWA, etc.), then a port forward
is not necessary. If not, the MS Exchange is not internal, and some more
work has to be done than just using an exim as a SMTP proxy and forwarding
the ports.

If there is only a single MS Exchange Server used, then - I have to agree -
exposing this server (holding the mailbox-storage) to the internet is nuts.
But If this is the scenario, major faults happened when the MS Exchange
infrastructure was planned. 

>   Is this an over paranoid stance?  What if the company falls under
> "Executive Order on Critical Infrastructure Protection"?

The risk hast to be evaluated - and proper arrangements have to be done.
Just having the ports forwarded without an essential reason is not an
option. 

Regards, Adrian

ret

Attachment: smime.p7s
Description: S/MIME cryptographic signature

<Prev in Thread] Current Thread [Next in Thread>