Help - Search - Members - Calendar
Full Version: Is this an open relay?
The Planet Forums > Security > General Security
acidbox
I tested one of the domains on my server (which runs qmail) against the open relay checker at abuse.net and I got the following results:

QUOTE
Connecting to mydomain.com for anonymous test ...

<<< 220 svr01.myserver.com ESMTP
>>> HELO www.abuse.net
<<< 250 svr01.myserver.com

Relay test 1
>>> RSET
<<< 250 flushed
>>> MAIL FROM:
<<< 250 ok
>>> RCPT TO:
<<< 553 sorry, that domain isn't in my list of allowed rcpthosts (#5.7.1)

Relay test 2
>>> RSET
<<< 250 flushed
>>> MAIL FROM:
<<< 250 ok
>>> RCPT TO:
<<< 553 sorry, that domain isn't in my list of allowed rcpthosts (#5.7.1)

Relay test 3
>>> RSET
<<< 250 flushed
>>> MAIL FROM:<>
<<< 250 ok
>>> RCPT TO:
<<< 553 sorry, that domain isn't in my list of allowed rcpthosts (#5.7.1)

Relay test 4
>>> RSET
<<< 250 flushed
>>> MAIL FROM:
<<< 250 ok
>>> RCPT TO:
<<< 553 sorry, that domain isn't in my list of allowed rcpthosts (#5.7.1)

Relay test 5
>>> RSET
<<< 250 flushed
>>> MAIL FROM:
<<< 250 ok
>>> RCPT TO:
<<< 553 sorry, that domain isn't in my list of allowed rcpthosts (#5.7.1)

Relay test 6
>>> RSET
<<< 250 flushed
>>> MAIL FROM:
<<< 250 ok
>>> RCPT TO:
<<< 553 sorry, that domain isn't in my list of allowed rcpthosts (#5.7.1)

Relay test 7
>>> RSET
<<< 250 flushed
>>> MAIL FROM:
<<< 250 ok
>>> RCPT TO:
<<< 553 sorry, that domain isn't in my list of allowed rcpthosts (#5.7.1)

Relay test 8
>>> RSET
<<< 250 flushed
>>> MAIL FROM:
<<< 250 ok
>>> RCPT TO:<"securitytest@abuse.net">
<<< 553 sorry, that domain isn't in my list of allowed rcpthosts (#5.7.1)

Relay test 9
>>> RSET
<<< 250 flushed
>>> MAIL FROM:
<<< 250 ok
>>> RCPT TO:<"securitytest%abuse.net">
<<< 250 ok

Relay test result
Hmmn, at first glance, host appeared to accept a message for relay.

THIS MAY OR MAY NOT MEAN THAT IT'S AN OPEN RELAY.

Some systems appear to accept relay mail, but then reject messages internally rather than delivering them, but you cannot tell at this point whether the message will be relayed or not.


It looks like it is failing to pass test 9. Is this a false positive or is it an actual open relay?

If it is, how can I fix this and/or test it to make sure i'm secure?

Thanks
Gary Simat
no you are not an open relay.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2010 Invision Power Services, Inc.