MS Exchange Server 5.5/ NT User Name Harvesting ?

From: Zero Divide (o0o@hotmail.com)
Date: 06/07/02


Date: 7 Jun 2002 16:33:18 -0000
From: Zero Divide <o0o@hotmail.com>
To: focus-ms@securityfocus.com


('binary' encoding is not supported, stored as-is)

Hello,

I work for a small company with about 100 computers on our network. Our
lone server is running on NT with all the latest hotfixes, service packs,
etc. Our mail server is MS Exchange 5.5, also with all the latest
hotfixes and service packs installed. Due to budgetary constraints
upgrading to newer software is not an option here.

The problem we're having is that everytime one of our employees keeps
his/her computer logged on overnight, crackers are able to harvest the
username and they then proceed to run cracking attempts on it all night.
 
From the security logs it looks like they are trying to use our mail
server as a spam relay. The only thing thats really stopping them is we
have all user accounts locked out from 5pm-7am. But we really don't know
whats going on during business hours.

We have a Watchguard firewall up and running and its provided us with alot
of information, including the cracker's IP addresses, but we would really
like to know how to stop them from harvesting our Usernames.

The usernames are not guessable, the only common thread that all the
usernames the crackers have harvested have is the fact that the Employee
left his/her computer on all night and logged into the network.

Any suggestions would be most appreciated.

Thanks



Relevant Pages

  • Re: Cant Figure this thing out!!! HELP!!!
    ... > passwords are stored but for some odd reason, ... > accept any usernames and passwords unless the computer is on the ... > network and has access rights to a certain server. ... If I disconnect the computer from the network, ...
    (microsoft.public.access.formscoding)
  • Re: Fully parallel Scheme-based language w/ evaluator
    ... Windows Server 2003 and networks in simple - and irreverent - terms. ... If networking really is a big deal, ... Concepts and Terminology in Part I, and The Design and Deployment of Network ...
    (comp.lang.misc)
  • Re: Outgoing POP3 email missing/lost/not received
    ... Funny thing is that I have had this ISP for 8 years and it has always been ... It looks like when you last ran CEICW, you set the ISP's mail server to: ... Internet Connection Wizard. ... After the wizard completes, the following network connection ...
    (microsoft.public.windows.server.sbs)
  • Re: Logon Server Unavailable
    ... There are currently no logon servers available to service ... You use a office laptop to connect the office VPN, when you map a network ... you may receive this message: "This account is the ... The server is not configured for transactions"> "A domain controller for your domain could not be contacted" ...
    (microsoft.public.windows.server.dns)
  • Re: Logon Server Unavailable
    ... There are currently no logon servers available to service ... You use a office laptop to connect the office VPN, when you map a network ... you may receive this message: "This account is the ... The server is not configured for transactions"> "A domain controller for your domain could not be contacted" ...
    (microsoft.public.windows.server.networking)