Full Disclosure mailing list archives

S/Mime Exchange 2003 how secure how to secure it?


From: "Daniel Sichel" <daniels () Ponderosatel com>
Date: Tue, 28 Mar 2006 08:54:07 -0800

Directive has just come down from on high, we WILL use email on our Cell
Phones/PDAs and non VPN'd laptops.  I am not a messaging guy but at a
small telco you wear lots of hats so I could use some real help here. We
are upgrading shortly to Exchange 2003 on Windows Server  2003 and want
secure email to and from our cell phones etc. So here are my questions

 

How secure is the built in S/Mime in Exchange 2003 assuming we are using
a certificate  for session encryption ? Don't laugh and hoot, I am
looking for real data not speculation. Are there exploits, and if so
what is needed to carry them out, physical access, just need the phone
number, or what?  Can this be brute forced? 

 

I would like two factor authentication using the users password and
something inherently in the cell phone like a burned in serial number or
the DN or something. Is there any support  for such a thing that will
work on cell phones and/or PDAs ?

 

I know OWA sucks on Exchange 5.5 and 2000, how about 2003? Same
questions as above, is it exploitable, and if so how? Can we require a
machine accessing the OWA site to flush its cache when done? Hopefully
this can be forced without requiring an OK click, I just want to do it,
no user intervention required (or allowed).

 

Any help would be welcomed, any Microsoft bashing would be a waste of
time since the higher powers have spoken and you know how that goes, So
it is written, so shall it be done. 

 

Thanks  

 

Daniel Sichel, MCSE, CCNP
Network Engineer
Ponderosa Telephone

 

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Current thread: