MS Exchange 5.5 NDRs (from MyDoom)

From: Darryl J Roberts (DarrylJR_at_SEU.COM)
Date: 02/02/04

  • Next message: Carboni, Mark: "MDAC worm exploit via MS04-003"
    Date:         Mon, 2 Feb 2004 08:57:18 -0800
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    Due to the MyDoom mass mailing worm (which randomly generates To:
    addresses), several of our customer are experiencing an unusually high
    rate of inbound SMTP traffic which is destined for an address where
    there is no corresponding mailbox. Their mail server sends a
    Non-Delivery Report (NDR) for each one of these messages. These NDRs
    are not only putting a load on our customer's Internet access link and
    the server, but a load on the Internet itself and the recipient of these
    NDR (who did not send the message in the first place because the worm
    spoofs the From: address). The cumulative effect of all the servers
    that send NDRs for the messages generated by this mass mailing worm is
    significant. Therefore, we have recommended to all of our customers to
    disable sending NDRs to the Internet.

    Unfortunately in Microsoft Exchange Server 5.5 there is no way to
    disable sending NDRs to the Internet. Contrary to some reports, setting
    "Disable Automatic Replies to the Internet" in the IMS Internet Mail
    Advanced options does not disable sending NDRs to the Internet.

    I have opened a support incident with Microsoft PSS (case number
    SRX040131604287). The engineer assigned to this case has verified that
    there is no way to disable sending NDRs in Exchange Server 5.5. I have
    asked that this case be escalated and Microsoft provide this
    functionality expediently.

    Unfortunately Exchange Server 5.5 is now in the Extended Support phase
    and there are no new non-security fixes for products in this support
    phase.

    If you need this functionality in Exchange Server 5.5, you might want to
    contact Microsoft Product Support Services, reference the case number
    above, and let them know that you also need this fix.

    --
    Darryl J. Roberts, MCSE, MCP+I, CompTIA CTT+, CSSA
    Software Engineering Unlimited, Microsoft Certified Partner
    PO Box 6476, Ventura, CA, USA  93006-6476
    tel. 1-805-650-6030, fax 1-805-650-1835
    -----
    NTBugtraq Editor's Note:
    Most viruses these days use spoofed email addresses. As such, using an Anti-Virus product which automatically notifies the perceived sender of a message it believes is infected may well cause more harm than good. Someone who did not actually send you a virus may receive the notification and scramble their support staff to find an infection which never existed in the first place. Suggest such notifications be disabled by whomever is responsible for your AV, or at least that the idea is considered.
    -----
    

  • Next message: Carboni, Mark: "MDAC worm exploit via MS04-003"

    Relevant Pages

    • RE: Catchall not working, EXTERNALLY?
      ... Microsoft CSS Online Newsgroup Support ... but we will start using the exchange server fully ... When I open the connection (over internet) to my exchange account, ...
      (microsoft.public.windows.server.sbs)
    • RE: Catchall not working, EXTERNALLY?
      ... Exchange server 2003 supports multiple clients, such as OWA, MAPI ... Microsoft CSS Online Newsgroup Support ... When I open the connection (over internet) to my exchange account, ...
      (microsoft.public.windows.server.sbs)
    • Re: Exchange 2003 thru NAT
      ... When you use the ISA and the Exchange Server in your environment, ... Using ISA Server 2000 with Exchange Server 2003 ... Microsoft can make no representation concerning ... dangers in the use of any software found on the Internet, ...
      (microsoft.public.exchange2000.general)
    • Re: Exchange 4 Calendar only, Mail is externally, problem sending
      ... my case the Exchange server does NOT accept mail directly from the internet. ... The client has Outlook with both external pop3 and internal ... the user populates the mail type as "EX" instead of SMTP. ...
      (microsoft.public.exchange.admin)
    • Re: Exchange PLUS POP3
      ... That cannot be so because the SBS Internet Users rule is to allow ... their mail servers so if our Exchange server goes down we can log onto ... We need to login to the POP3 mailboxes ...
      (microsoft.public.windows.server.sbs)