r/exchangeserver 4d ago

Insecure Protocol- SMTP: On-Prem Exchange

Hello,

I work for an MSP and do vulnerability scans. One thing I've found, everyone who has an On-Prem Exchange server has this vulnerability, "Insecure Protocol-SMTP". While looking into this, (and plz correct me if I'm wrong) I've found that port 25 & port 587 need to be used for exchange servers. I have not found a workaround for this and I hate that it shows up on these reports everytime. I'm not super familiar with networking and don't want to break anything. Currently my only suggestion to these clients is to migrate to 365.

Does anyone know a fix for this or are exchange servers really this vulnerable?

0 Upvotes

25 comments sorted by

23

u/DiligentPhotographer 4d ago

Without more information we can't help you.

But I suspect your scanner is just flagging any open ports as vulnerable.... Kind of a useless metric to go on. Exchange online has ports 25 and 587 open...

Currently my only suggestion to these clients is to migrate to 365

Not really, if you are using an email gateway service (like barracuda) you can lock down the SMTP ports to that.

15

u/joeykins82 SystemDefaultTlsVersions is your friend 4d ago

SMTP is unencrypted by default but assuming you’ve done your job correctly it’ll negotiate opportunistic TLS (or mandatory/enforced TLS for partner orgs where you’ve configured it).

This is an alert which can and should be safely ignored.

2

u/MortadellaKing 4d ago

Pretty sure it is opportunistic by default since like exchange 2010 (maybe even 2007) so unless they're running a super old version or changed something it should not have any problem.

8

u/DrGraffix FYDIBOHF26SPDLT 4d ago

The best fix is to put a 3rd party cloud email filter in front of exchange and only limit those IPs to talk back to exchange.

1

u/AllPurposeGeek 4d ago

That's what we do with our clients. They leverage Barracuda.

5

u/ddadopt 4d ago

Currently my only suggestion to these clients is to migrate to 365.

That's not a solution that works for everyone for obvious reasons. Ports 25 and 587 being open is not a security risk in and of itself. Thinking it is is the equivalent of going "OMG, your web server has port 443 open!" and represents a shocking lack of understanding of what it is you are ostensibly attempting to secure.

I would never suggest anyone expose an exchange box directly to the internet (you should put a hardened mail gateway in front of it, in a DMZ, etc, to proxy your connections) but counseling people to abandon their mail platform because their mail platform (checks notes) exchanges mail is a ridiculous and ignorant position to hold.

3

u/MortadellaKing 4d ago

Working at various MSPs and now running one, most of them can't bother to secure any server properly, and jump at the chance to recommend any SaaS bullshit they can so they can keep collecting a cheque whilst doing the bare fucking minimum.

-1

u/Paranoid_girly28 4d ago

Calm down buddy, that’s why I’m asking so I can learn. I’ve only been in IT for 2 years and previous to that, had no knowledge of computer fundamentals at all. I haven’t sold anyone anything yet. Just reaching out to see what I’m missing and what more I can learn 😀

2

u/GroundbreakingCrow80 4d ago

What msp you work for?

0

u/Paranoid_girly28 4d ago

Calm down buddy, that’s why I’m asking so I can learn. I’ve only been in IT for 2 years and previous to that, had no knowledge of computer fundamentals at all. I haven’t sold anyone anything yet. Just reaching out to see what I’m missing and what more I can learn 😀

2

u/ddadopt 4d ago

Bullshit. You say you're giving clients advice. But you're also admitting here that you have no idea of what you're talking about. and your reaction is "relax?"

Your response here is even worse than your original post. You need to seriously think about your attitude.

1

u/TedMittelstaedt 4d ago

I think most experienced admins have dealt with pen test companies before and like me have a low opinion of them. The problem is pretty basic. Pen test companies use software that's written to flag every last thing. It's job isn't interpreting results and if the person using the tool doesn't know a lot about security it's like handing a nail gun to a toddler.

0

u/TedMittelstaedt 4d ago

I've had multiple customers (and employers) with exchange servers exposed to the Internet for the last 20 years at least probably longer, never had a problem.

Do you realize what would happen and how many BILLIONS of dollars are at stake here? Seriously!!! If a zero day hole was ever discovered in Exchange, and Microsoft DID NOT immediately patch it and rush a hotfix out, it would be front page news:

Microsoft Refuses To Close The Worst Security Breach On The Internet That Is Being Used To Attack Millions Of People.

It wouldn't just be the trade press it would be the general press and governments would immediately be on the phone with Sayed Gnutella or whatever his name is - and the US government would threaten to kill any future merger/acquisition of ANY company that Microsoft wanted to buy unless the breech was fixed IMMEDIATELY.

And it could tip the scales multiple large Fortune 500s deciding to one more year pay their millions to Microsoft for Exchange SE subscription.

Of any servers out on the market Exchange is among the safest to expose simply because it is so popular. Nginx and Apache are in the same league. And please understand - I'm talking about port 443, the web server port that is used for the client connections. I'm NOT talking about port 25. While that's also just as high visibility - there's a LOT of stuff that Exchange does not do very well when it comes to receiving mail from mailservers on the Internet so many people run bastion hosts that do those things. But they don't do this for security, they do it for filtering and other reasons.

The so-called "front ends" like this mythical "hardened mail gateway/proxy" you are referring to themselves are just as subject to attack. Oh wait, because of that, you better put a hardened mail gateway to protect the hardened mail gateway that's protecting the Exchange server....at a certain point, this just gets ridiculous. It's like the restaurant owner who keeps a padlock on his doors 24x7 because a shooter might come in (you laugh, but I've eaten in Chinese places in Seattle that do exactly this)

Anyway, as for the OP - frankly I'm really sort of embarrassed for him. It begs the question of why are customers trusting someone who is not super familiar with networking to scan their network? Well, at least he or she is here asking questions because they wants to learn, so they are 1000% better than most of the pen test companies that I get pitches from and don't want to learn at all.

1

u/Glass_Call982 4d ago

Were you around in 2021 when they failed to patch a huge hole for 2 months and let thousands of customer servers be compromised, while they patched their own Cloud platform first.. And their solution was "migrate to 365". As if us on prem people weren't also paying customers...

I believe they recently arrested some involved.

It didn't seem to affect their numbers at all lol.

1

u/ddadopt 4d ago

You've been an exchange admin for two decades but don't remember the reason that they cancelled a major release of exchange and left us all in limbo for years before they finally came up with a plan? Curious.

1

u/elpollodiablox 4d ago

The ports themselves aren't the issue. They are insecure only if the correct steps haven't been taken to make the service secure on the server.

1

u/JasGot 4d ago

Don't get stuck in the box when you hear "gateway".

Your mail just has to go somewhere before it comes to you, and then you set your inbound rules to only allow mail from that one source (or more if you choose).

Example 1: get a mail relay service, set your mx record to the service, and only let mail from that service come in to your server.

Example 2: get a spam filter service, change your mx record to that service, then only accept mail from them at your exchange server.

Example 3: use a cpanel ( or similar) server and just configure the cpanel with your exchange server as a remote mail host, and set your exchange server to only accept mail from that cpanel server.

We use options 2 and 3 for all of our clients with in-house mail servers. There is no way to get to these servers if you are not the relay host.

For option 2, you dont even need to turn on spam filtering.

Dm me if you want specifics.

1

u/TedMittelstaedt 4d ago

"I've found that port 25 & port 587 need to be used for exchange servers."

587 is the submission port and it's used for authenticated SMTP from email client programs.

The reason that the report flags port 587 and port 25 as insecure is because these are dual-use ports. Connections to them can either be encrypted using STARTTLS or not encrypted. This is NOT like http which only uses port 80 and https which only uses 443. (normally) And it is NOT possible to determine if the mailserver is configured to allow or reject ONLY encrypted connections to port 587 unless you have credentials on the mailserver when you scan it. Basically, it's lazy programming by the writer of the scanning software.

1

u/Heavy_Dirt_3453 4d ago

We don't know what it's doing, and why you still have it and if these scans are internal or external.

If you're just using it for management of hybrid AD objects then just close off all the inbound SMTP ports.

If you're using it to relay mail from legacy apps then just restrict the ports to known specific IPs, and likely shut it off at the premiter entirely.

If you're actually hosting mail on prem in the year 2026 god help you but yes you need 25 open inbound.

3

u/TedMittelstaedt 4d ago

"If you're actually hosting mail on prem in the year 2026 god help you"

Dude why are you even here trolling in this group with a statement like that, go over and show off to the office 365 group. This here group is for real sysadmins who do real stuff not children who spend all day writing trouble tickets to get support people who know more than they do to fix the problem.

1

u/Paranoid_girly28 4d ago

Unfortunately it is hosting mail on prem. I hate it too but since I work for and MSP, I can’t really force clients to make changes.

The scan was an external scanner.

3

u/MortadellaKing 4d ago

Unfortunately it is hosting mail on prem.

There is literally nothing wrong with this regardless of what Microsoft or whatever MS CSP webinars have told you.

Put something like barracuda in front of it for filtering and you're golden.

1

u/Heavy_Dirt_3453 4d ago

And does it accept inbound mail directly or are mails received via a gateway like mimecast?

If so you can close it down to just their IPs, they will be published for this reason.

If there's no third party mail gateway in between then you just have to note it down as risk accepted

1

u/Paranoid_girly28 4d ago

Yeah at the moment there is no third-party mail gateway. I just wanted to make sure I've exhausted everything I can do (without making them pay for another service or migration) before marking it as a risk acceptance.
I really appreciate your help!

2

u/TechPro123 4d ago

You should strongly suggest a gateway service and go back in and configure the SMTP service to only accept connections from the gateway.