21. Protecting E-Mail Services.pdf

(215 KB) Pobierz
Protecting E-Mail
Services
Security Fundamentals
Instructor: Don Jones
Protecting E-Mail Services
Security Fundamentals
In This Lesson:
Spam
Relaying
Protecting E-Mail Services
Security Fundamentals
Spam
Spam is unwanted e-mail and it is usually prevented by a
spam filter .
Generally, you adjust your DNS settings so that incoming e-mail
goes to the spam filter first and then to your e-mail server(s).
Many e-mail server software includes spam filtering capabilities.
Sender Policy Framework (SPF) is a tool for preventing
spam. It allows an organization to, via its public DNS records,
identify the servers that are authorized to send its email. Spam
filters can utilize this to discard e-mail that purports to be from
an organization, but based on that organization’s SPF isn’t.
Blacklists list known spam-sending servers so that spam filters
can block e-mail originating from them.
1123952515.050.png 1123952515.061.png 1123952515.071.png 1123952515.082.png 1123952515.001.png 1123952515.002.png 1123952515.003.png 1123952515.004.png 1123952515.005.png 1123952515.006.png 1123952515.007.png 1123952515.008.png 1123952515.009.png 1123952515.010.png 1123952515.011.png 1123952515.012.png 1123952515.013.png 1123952515.014.png 1123952515.015.png 1123952515.016.png 1123952515.017.png 1123952515.018.png 1123952515.019.png 1123952515.020.png 1123952515.021.png 1123952515.022.png 1123952515.023.png 1123952515.024.png 1123952515.025.png 1123952515.026.png 1123952515.027.png 1123952515.028.png 1123952515.029.png 1123952515.030.png 1123952515.031.png 1123952515.032.png 1123952515.033.png 1123952515.034.png
 
Protecting E-Mail Services
Security Fundamentals
SPF
Only accept e-mail from my
domain if it is sent by one of
these servers.
These may not be in my
domain, but they’re authorized
to send on my behalf.
Protecting E-Mail Services
Security Fundamentals
Relaying
Many organizations rely on relaying , which is when one e-mail
server hands off its outbound e-mail to another for actual
sending.
Relaying helps distribute the workload associated with e-mail.
An open relay is one which will accept e-mail from anyone,
and then route it to its destination – an obvious security
vulnerability!
It will look like you’re sending the spam
Can result in your e-mail servers being placed on spam
blacklists
Protecting E-Mail Services
Security Fundamentals
Stopping Open Relays
A simple fix is to configure mail (SMTP) servers to only accept
relay mail from:
A list of known IP addresses
Authenticated users or services
Other “known and approved” sources
By blocking other mail sources, you stop your server from being
an open relay.
Let’s see how this is often configured…
1123952515.035.png 1123952515.036.png 1123952515.037.png 1123952515.038.png 1123952515.039.png 1123952515.040.png 1123952515.041.png 1123952515.042.png 1123952515.043.png 1123952515.044.png 1123952515.045.png 1123952515.046.png 1123952515.047.png 1123952515.048.png 1123952515.049.png 1123952515.051.png 1123952515.052.png 1123952515.053.png 1123952515.054.png 1123952515.055.png 1123952515.056.png 1123952515.057.png 1123952515.058.png 1123952515.059.png 1123952515.060.png 1123952515.062.png 1123952515.063.png 1123952515.064.png 1123952515.065.png 1123952515.066.png 1123952515.067.png 1123952515.068.png 1123952515.069.png
 
Protecting E-Mail Services
Security Fundamentals
What We Covered
Spam
Relaying
1123952515.070.png 1123952515.072.png 1123952515.073.png 1123952515.074.png 1123952515.075.png 1123952515.076.png 1123952515.077.png 1123952515.078.png 1123952515.079.png 1123952515.080.png 1123952515.081.png 1123952515.083.png
 
Zgłoś jeśli naruszono regulamin