Skip to main content

Join us at Gartner SEC London and discover how LevelBlue can help you secure what’s next. Learn More

Loading...
Loading...

INFO: Is MailMarshal vulnerable to attacks using VRFY, EXPN, or other SMTP commands?

Expand / Collapse


This article applies to:

  • MailMarshal (SEG)

Question:

  • How does SEG/MailMarshal reply to the SMTP VRFY or EXPN commands?
  • Does MailMarshal take any action on repeated bad SMTP commands?

Information:

  • MailMarshal always responds to VRFY with the ambiguous SMTP response "252 user appears to be valid". Outside applications cannot harvest address information using this command.
  • MailMarshal does not support EXPN.
  • MailMarshal has a default mechanism to recognize and restrict excessive repeated requests or nonsense commands. Customers can contact Technical Support for details if required.

Notes:

See also the DHA and DoS attack prevention features documented in the MailMarshal User Guide.


To contact LevelBlue about this article or to request support:


Rate this Article:
     

Add Your Comments


Comment submission is disabled for anonymous users.
Please send feedback to Trustwave Technical Support or the Webmaster
.