Re: Exchange SMTP Hole?

From: Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP] (sbradcpa_at_pacbell.net)
Date: 11/11/03

  • Next message: Gerald Eisenhaur: "Re: Exchange SMTP Hole?"
    Date: Tue, 11 Nov 2003 08:28:02 -0800
    To: Tom Burns <tburns@torcausa.com>
    
    

    Spammers are authenticating on port 25
    Turn on auditing.
    Ensure that the guest account is disabled and complex passwords are
    being used by all accounts.
    http://www.sbsfaq.com/news/getArticle.asp?MessageID=000000001A447390AA6611CD9BC800AA002FC45A0900E049B559A334DD479C5D360FB473600B0000000187180000F401C41B681A9640A459B27C5FF7E6840000B1E572030000&path=News

    Tom Burns wrote:

    >Good morning all,
    >
    >I have an exchange server that's been running for quite some time (over
    >a year) and had it locked down to prevent relay (spam). It is patched
    >all the way up to 3a.
    >
    >I checked my queues yesterday and got slammed by spam relaying.
    >
    >Is there a security hole that MS does not know about yet in SMTP?????
    >
    >The only way I resolved this was to block connection from 219.x.x.x,
    >218.x.x.x, 211.x.x.x, etc.
    >
    >This server has been testing aginst ORDB.ORG and shown to NOT be an open
    >relay.
    >
    >If anyone has any suggestions, please let me know.
    >
    >
    >Thomas A. Burns
    >System Administrator
    >Torca Products Inc.
    >Auburn Hills, MI 48326
    >248-373-8300 x186
    >
    >---------------------------------------------------------------------------
    >Network with over 10,000 of the brightest minds in information security
    >at the largest, most highly-anticipated industry event of the year.
    >Don't miss RSA Conference 2004! Choose from over 200 class sessions and
    >see demos from more than 250 industry vendors. If your job touches
    >security, you need to be here. Learn more or register at
    >http://www.securityfocus.com/sponsor/RSA_focus-ms_031027
    >and use priority code SF4.
    >---------------------------------------------------------------------------
    >
    >
    >

    -- 
    "Don't lose sight of security. Security is a state of being,
    not a state of budget. He with the most firewalls still does
    not win. Put down that honeypot and keep up to date on your 
    patches. Demand better security from vendors and hold them 
    responsible. Use what you have, and make sure you know how 
    to use it properly and effectively."
    ~Rain Forest Puppy
    http://www.wiretrip.net/rfp/txt/evolution.txt
    ---------------------------------------------------------------------------
    Network with over 10,000 of the brightest minds in information security
    at the largest, most highly-anticipated industry event of the year.
    Don't miss RSA Conference 2004! Choose from over 200 class sessions and
    see demos from more than 250 industry vendors. If your job touches
    security, you need to be here. Learn more or register at
    http://www.securityfocus.com/sponsor/RSA_focus-ms_031027 
    and use priority code SF4.
    ---------------------------------------------------------------------------
    

  • Next message: Gerald Eisenhaur: "Re: Exchange SMTP Hole?"

    Relevant Pages

    • Re: New Microsoft Exchange Server Vulnerability
      ... It requires the guest account be turned on, and that the smtp virtual server ... visitors use a mail server anonymously, but because of security issues, the ... most highly-anticipated industry event of the year. ...
      (Focus-Microsoft)
    • Re: CEH and Intense School
      ... > You want more than 4 to know the bugs are ironed out in labs and so on. ... > Network with over 10,000 of the brightest minds in information security ... most highly-anticipated industry event of the year. ...
      (Pen-Test)
    • RE: Security Posture Assessment
      ... For many of our general IT audits we include a modem ... Subject: Security Posture Assessment ... However phone sweep is the best risk assessment tool for war dialing. ... most highly-anticipated industry event of the year. ...
      (Pen-Test)
    • RE: strange ftp site
      ... Here are some quick prelim results of running strings against the exe file. ... A security error of unknown cause has been detected which has ... Network with over 10,000 of the brightest minds in information security ... most highly-anticipated industry event of the year. ...
      (Incidents)
    • RE: MS03-049 Scanner?
      ... I haven't seen a single tool for this yet but I am sure there will be ... scan from a Windows workstation and even select which plugins to use. ... Network with over 10,000 of the brightest minds in information security ... most highly-anticipated industry event of the year. ...
      (Focus-Microsoft)