Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 05-23-2007, 10:29 AM
Intermediate Member
 
Posts: 23
Exclamation Anonymous access to LDAP server? security flaw?

my friend ran a security audit on my machine and was able to produce the following without any passwords:



Please note that the results below represent only the first 5 entries that could be extracted from the server.

RESULT:
ou: people
objectClass: organizationalRole
cn: people
zimbraMailTransport: lmtp:mail.MYDOMAIN.com:7025
zimbraMailDeliveryAddress: admin@mail.MYDOMAIN.com
sn: admin
zimbraId: e1BLAHc6-BLAH-BLAH-BLAH-3eaBLAH9b41
zimbraMailStatus: enabled
uid: admin
objectClass: organizationalPerson
objectClass: zimbraAccount
objectClass: amavisAccount
cn: admin
zimbraMailHost: mail.MYDOMAIN.com
mail: admin@mail.MYDOMAIN.com
mail: root@mail.MYDOMAIN.com
mail: postmaster@mail.MYDOMAIN.com
zimbraMailAlias: root@mail.MYDOMAIN.com
zimbraMailAlias: postmaster@mail.MYDOMAIN.com
zimbraMailForwardingAddress: MYUSERACCOUNT@MYDOMAIN.com
ou: people
objectClass: organizationalRole
cn: people
ou: people
objectClass: organizationalRole
cn: people
Reply With Quote
  #2 (permalink)  
Old 05-23-2007, 10:42 AM
Former Zimbran
 
Posts: 5,606
Default

Nope.
We allow anonymous binding to the LDAP server for address book reasons.
Most LDAP servers allow this type of activity, including RedHat Directory Server and Apple Open Directory.

Cheers!
john
Reply With Quote
  #3 (permalink)  
Old 05-23-2007, 10:45 AM
Intermediate Member
 
Posts: 23
Default

so how do i prevent people from leeching email addresses for spaming?
Reply With Quote
  #4 (permalink)  
Old 05-23-2007, 10:48 AM
Former Zimbran
 
Posts: 5,606
Default

Anonymous bind mechanism is enabled by default, but can be disabled by specifying "disallow bind_anon" in slapd.conf.in.

I'm not sure of the impact on your server.

As far as SPAM, I don't think it's realistic that you will get SPAM, as it hasn't been an issue for may e-mail providers including us.
Reply With Quote
  #5 (permalink)  
Old 05-23-2007, 04:09 PM
Former Zimbran
 
Posts: 5,606
Default

Quote:
Originally Posted by jholder View Post
Anonymous bind mechanism is enabled by default, but can be disabled by specifying "disallow bind_anon" in slapd.conf.in.

I'm not sure of the impact on your server.

As far as SPAM, I don't think it's realistic that you will get SPAM, as it hasn't been an issue for may e-mail providers including us.
I've just been informed by our engineering team that if you disable anonymous bind, you will break postfix's LDAP lookups.

There is a bug that we're trying to fix for 5.0 that will remove the need for anon bind: http://bugzilla.zimbra.com/show_bug.cgi?id=15378

john
Reply With Quote
  #6 (permalink)  
Old 05-23-2007, 04:32 PM
Former Zimbran
 
Posts: 5,606
Default

A better solution would be to simply block access to port 389 either by external firewall, or iptables.

john
Reply With Quote
  #7 (permalink)  
Old 12-19-2007, 07:22 PM
Elite Member
 
Posts: 281
Default

Quote:
Originally Posted by jholder View Post
A better solution would be to simply block access to port 389 either by external firewall, or iptables.

john
But would this block access from users in remote areas that are not connected to our LAN? I was wondering about this when I realized that I could read my ldap from my house.

dj
Reply With Quote
  #8 (permalink)  
Old 12-20-2007, 05:52 AM
Moderator
 
Posts: 441
Default

Only if you're trying to use a 3rd party client, and pull LDAP info for your address book. Zimbra's webclient should be able to look it up itself. (correct me if i'm wrong here)
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.