|
|
Question : Exchange 2007 has its Private IP in SMTP header - Security Issue
|
|
When a messages arrives at remove system, the SMTP header includes the Exchange server's pirvate IP address. I am not sure but this may be because we have an Exchange SMTP gateway ourside of the Exchange 2007 server and it adds that information as the message passes through.
The SMTP Gateway's internal interface is on the LAN so it sees the private address of the Exchange 2007 server, and the Exchange 2007 private address is the message source for the SMTP gateway.
How can I control what is in the SMTP header. Its not a good security practice to be publishing your internal address scheme.
|
Answer : Exchange 2007 has its Private IP in SMTP header - Security Issue
|
|
As far as I am aware, the behaviour cannot be changed. Checking my own email accounts which include emails from people at Microsoft (which will be coming off Exchange 2007) they all include internal IP address information and the internal server names of the Exchange servers. If it could be changed then Microsoft Corp IT would have changed it. Looking at other emails from sites I know are already using Exchange 2007 also show the same information being exposed. This hasn't changed from any of the previous versions of Exchange. Exchange 5.5, 2000 and 2003 exposed that information. If you aren't happy about it then you will have to contact Microsoft. That is one of the few ways that Microsoft realise what people consider to be important or not. I wouldn't call it a bug because the SMTP engine is doing what it is designed to do - write headers on every step that the message takes.
Simon.
|
|
|
|