- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Re: Telnet 25 port
Categories
Company
Local Language
Forums
Discussions
Knowledge Base
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Knowledge Base
Forums
Discussions
- Cloud Mentoring and Education
- Software - General
- HPE OneView
- HPE Ezmeral Software platform
- HPE OpsRamp
Knowledge Base
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-19-2001 12:28 AM
09-19-2001 12:28 AM
I want to know if it's possible to deny telnet to the port 25 at one server that works as a sendmail relay.
Thank-you very much!
Carmen.
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-19-2001 12:33 AM
09-19-2001 12:33 AM
Re: Telnet 25 port
Easily done, either in /etc/inetd.conf on the server you want to disable it comment out the line telnet and then do an inetd -c
OR
setup the /var/adm/inetd.sec file to block telnet only for certain IP adresses. See man on inetd.sec
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-19-2001 12:37 AM
09-19-2001 12:37 AM
Re: Telnet 25 port
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-19-2001 12:48 AM
09-19-2001 12:48 AM
Re: Telnet 25 port
To stop sendmail relaying mail thru port 25 you can simply stop sendmail on the server in question; /sbin/init.d/sendmail stop
Or you can add an entry to /var/adm/inetd.sec to block port 25 traffic for any or all IP addresses.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-19-2001 12:48 AM
09-19-2001 12:48 AM
Re: Telnet 25 port
Not sure what you want..
Can you block port 25 in firewall ?
Thanks
Animesh
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-19-2001 12:54 AM
09-19-2001 12:54 AM
Re: Telnet 25 port
No, its not a Firewall, its the mail server.
I can make a telnet to the 25 port and send a mail directly, without connect to the application....and I want to resolve it.
I don't want to deny telnets that use the 23 port, only to the 25 port, that its use the smtp. But I want (at the same time) that all the mail works corretly.
Thank-you
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-19-2001 01:43 AM
09-19-2001 01:43 AM
Re: Telnet 25 port
http://cr.yp.to/qmail.html
http://www.postfix.org
-Santosh
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-19-2001 02:49 AM
09-19-2001 02:49 AM
Re: Telnet 25 port
You cannot disable telneting to selected port (25) with standard HPUX procedures. Only by a firewall.
Later,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-19-2001 05:29 AM
09-19-2001 05:29 AM
Re: Telnet 25 port
/usr/sbin/inetd -c
Hope this helps.
...jcd...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-19-2001 06:11 AM
09-19-2001 06:11 AM
Re: Telnet 25 port
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-19-2001 08:56 AM
09-19-2001 08:56 AM
Re: Telnet 25 port
you can use ipfilter/9000 or inetd.sec or tcpwrappers to preclude connections to port 25 from specific IP addresses, and perhaps even from specific remote port numbers.
however, the port number range that telnet will use for its connectoin(s) is likely indistinguishable from that used by other mail applications
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-19-2001 05:17 PM
09-19-2001 05:17 PM
Re: Telnet 25 port
server act properly. The smtp protocol is designed
to all mail to be submitted via telnet or any other
process that can do an interactive conversation on
port 25.
You can limit how mail is relayed through the
mail server. Check the documentation on relay
rules. You don't want messages received from
outside your network relayed anywhere outside
your network.
Security is a little easier if you have separate incoming
and outgoing servers. The incoming server only
accepts mail destined for your network. The
outgoing server does not accept any mail connections
from outside your network.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-19-2001 11:12 PM
09-19-2001 11:12 PM
SolutionYou could make it "difficult" for someone to telnet by moving the smtp entry in /etc/services to, say, 5000, and set the daemonportoptions=port=5000 option in sendmail.cf
However, this will only work if you have control of the machines sending mails to this server, as you will also have to add the port number to the delivery agent line in their sendmail.cf, e.g.
Msmtp, P=[IPC], F=mDFMuX, S=11/31, R=21, E=\r\n, L=990,
T=DNS/RFC822/SMTP,
A=IPC $h 5000
Rgds, Robin.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-20-2001 01:49 AM
09-20-2001 01:49 AM
Re: Telnet 25 port
Thank-you very much!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-20-2001 02:26 AM
09-20-2001 02:26 AM
Re: Telnet 25 port
sorry to contradict, but to "hide" the service on another port is no real help.
A portscanner will surely detect your mailservice on the diffrent port within minutes.
Esp. for mail, you might not be able to receive any mail from elsewhere, because nobody would expect he needs to connect to a diffrent port.
Even then, somebody could do "telnet hostname 5000" to connect to your service.
If you need protection, you need a mailproxy. This service is included in several firewall products.
Do not know if this helps
Volker
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-20-2001 02:34 AM
09-20-2001 02:34 AM
Re: Telnet 25 port
Thank-you
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-20-2001 05:03 AM
09-20-2001 05:03 AM
Re: Telnet 25 port
Yes, Volker is correct, my suggestion was not particularly secure, but would deter a 'casual' attempt to break in.
Rgds, Robin.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-20-2001 09:50 AM
09-20-2001 09:50 AM
Re: Telnet 25 port
a) What exactly do you want to do?
You have several options:
* You can allow use of the mailserver, port 25 for certain hosts/IP's only (e.g. for localhost or ip.of.application.server)
* You can turn off listening to Port 25 altogether, simply by stopping sendmail and restarting it as "sendmail -q30m" instead of "sendmail -db -q30m"
* Or you can tweak rules in sendmail.cf that certain senders are allowed from certain IP's only. It's a pain with sendmail, but possible.
You might want to consider switching to www.postfix.org, which is easier to configure and much more secure. Besides, it's faster.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-20-2001 01:49 PM
09-20-2001 01:49 PM
Re: Telnet 25 port
There's a big diff between limiting access to a port (ipfilter or firewall)
and
making sure only one host can use you as a relay.
The latter is trivial in modern sendmail.
See RelayTo, DeniedIP, LocalIP to implement application level access control.