7 SMTP HELP detection SMTP 2003/11/13 Marc Ruef marc dot ruef at computec dot ch http://www.computec.ch computec.ch Marc Ruef marc dot ruef at computec dot ch http://www.computec.ch computec.ch 2004/11/13 2.0 Corrected the plugin structure and added the accuracy values in 1.3. Improved the pattern matching and added the changelog in 2.0 tcp 25 open|send HELP\n|sleep|close|pattern_exists 220 *HELP* 70 This plugin was written with the ATK Attack Editor. Most mail transfer agents Hardened mail transfer agents Configuration The mail server allows the HELP commando. A malicous user could use this to verify the availablity of certain SMTP commands. He could also enumerate the mail server. Do not allow the HELP command to prevent further enumeration. Check the manual of your mail server howto set the configuration correctly. Additionally prevent unwanted SMTP connections with firewalling. 10 minutes Yes Yes Yes Low 9 9 2 6 Nessus is able to do the check automated. Mostly attackers prefer to test the HELP support with a simple telnet or NetCat connection. Hacking Intern - Angriffe, Strategien, Abwehr, Marc Ruef, Marko Rogge, Uwe Velten and Wolfram Gieseke, November 1, 2002, Data Becker, Düsseldorf, ISBN 381582284X http://www.computec.ch