Exchange SMTP Hole?

From: Tom Burns (tburns_at_torcausa.com)
Date: 11/11/03

  • Next message: Marc Fossi: "SecurityFocus Microsoft Newsletter #162"
    Date: Tue, 11 Nov 2003 08:59:31 -0500
    To: <focus-ms@securityfocus.com>
    
    

    Good morning all,

    I have an exchange server that's been running for quite some time (over
    a year) and had it locked down to prevent relay (spam). It is patched
    all the way up to 3a.

    I checked my queues yesterday and got slammed by spam relaying.

    Is there a security hole that MS does not know about yet in SMTP?????

    The only way I resolved this was to block connection from 219.x.x.x,
    218.x.x.x, 211.x.x.x, etc.

    This server has been testing aginst ORDB.ORG and shown to NOT be an open
    relay.

    If anyone has any suggestions, please let me know.

    Thomas A. Burns
    System Administrator
    Torca Products Inc.
    Auburn Hills, MI 48326
    248-373-8300 x186

    ---------------------------------------------------------------------------
    Network with over 10,000 of the brightest minds in information security
    at the largest, most highly-anticipated industry event of the year.
    Don't miss RSA Conference 2004! Choose from over 200 class sessions and
    see demos from more than 250 industry vendors. If your job touches
    security, you need to be here. Learn more or register at
    http://www.securityfocus.com/sponsor/RSA_focus-ms_031027
    and use priority code SF4.
    ---------------------------------------------------------------------------


  • Next message: Marc Fossi: "SecurityFocus Microsoft Newsletter #162"

    Relevant Pages

    • How to configure Exchange 2007 to prevent spam relay
      ... I just installed MS Exchange 2007 and configured the Receive Connector ... Exchange server to relay their spam and as a result will use up most of the ... Servers but spam email still use a large amount of system resources. ...
      (microsoft.public.exchange.setup)
    • MSF antispam info
      ... Spam and fraudulent e-mail messages are major issues for computer users ... Exchange Server, and Microsoft Exchange Hosted Filtering. ... and personalized spam protection while reducing false positives. ...
      (comp.mail.misc)
    • Re: Suggestions / Gotchas - Linux as mail proxy to MS Exchange
      ... We need the Linux box to do the following: ... Filter spam with a reasonably good spam filter. ... > as possible spam but passed on to the exchange server. ... Filter e-mails with attachments. ...
      (alt.os.linux)
    • Re: Mail spoofing and unwanted/bogus NDRs
      ... this may cause the external spam sender know the ... Microsoft Exchange Server Intelligent Message Filter v2 Operations Guide ... This newsgroup only focuses on SBS technical issues. ... | millions of messages to it all with forged or spoofed e-mail addresses ...
      (microsoft.public.windows.server.sbs)
    • Re: Receiving thousands of System Administrator messages in e-mail
      ... Spammer sends 10,000 emails to a bad addresses at your company, i.e. ... Spammer configures the spam email to fool your exchange server into ... so sends the NDR to the sender which of course is actually the target ...
      (microsoft.public.windows.server.sbs)