How to disable VRFY and EXPN commands on the SMG scanner?
SMG 10.7 / 10.8 / 10.9
Some penetration testing can interpret 252 2.0.0 SMTP response from the SMG as a allowed command by seeing a response.
VRFY and EXPN commands are restricted by default.
SMG response for VRFY and EXPN command:
VRFY [email protected]
252 2.0.0 VRFY restricted
EXPN [email protected]
252 2.0.0 EXPN restricted