Re: Exchange question

From: Thor (thor_at_hammerofgod.com)
Date: 11/14/03

  • Next message: J. Bilder: "Re: Exchange question"
    To: "Tom Burns" <tburns@torcausa.com>, <focus-ms@securityfocus.com>
    Date: Fri, 14 Nov 2003 08:32:25 -0800
    
    

    >One thing that was brought up is that NDR's can be used to relay (the
    >spammer uses NDR's to forward the message content by using the mail
    >from: email@address.com) I think that we will be seeing more of this
    >type of relaying going on- it sends a message back to the address in the
    >from block.
    >
    >Anyone setup a double SMTP setup in there network? Ie. exchange only
    >receives messages from the 2nd SMTP that is out on the net and the 2nd
    >server relays the message internally from the outside?

    I've got a similar setup to what you describe above (with ISA and SMTP
    filtering thrown in the mix) but that won't keep the NDR's from being sent
    back. Unless I miss something in your setup... One would basically use
    smart host delivery for all mail, or depending on the gateway features, DNS
    for some domains and smarthost for others, but the NDR would go out unless
    you have an option not to send one.

    For exchange, you can turn this off by going into SysMan, Global Settings,
    Internet Message Formats, select the properties of the default rule, and
    clear "allow non-delivery reports."

    NDR's had a place, but these days, I really question their effectiveness any
    more. Most don't resolve to a valid email (spam) and even in the case of a
    spammer using the NDR to deliver the message, the email body is in the form
    of an EML attachment, which would have to be manually opened. I just turn
    it off when I can.

    That being said, I have not seen a way to turn off NDR's altogether via the
    standard IIS SMTP service. If anyone has a reg hack for that, it would be
    great. Since Win2k3 now has a pop3 service (a bit ghetto, but quite
    functional) it is easy to set up and configure a pretty cool mail solution
    right out of the box. however, one is only using the SMTP service, and you
    just can't turn NDR's off (that I know of.)

    t

    ---------------------------------------------------------------------------
    Network with over 10,000 of the brightest minds in information security
    at the largest, most highly-anticipated industry event of the year.
    Don't miss RSA Conference 2004! Choose from over 200 class sessions and
    see demos from more than 250 industry vendors. If your job touches
    security, you need to be here. Learn more or register at
    http://www.securityfocus.com/sponsor/RSA_focus-ms_031027
    and use priority code SF4.
    ---------------------------------------------------------------------------


  • Next message: J. Bilder: "Re: Exchange question"

    Relevant Pages

    • Re: SMTP "Relay Denied" on localhost! (windows server 2003)
      ... to relay through the IIS SMTP Service. ... On the Access tab, click the Relay button. ... Dim bodyMSG As String ... on my local machine (using the integrated web server of Visual ...
      (microsoft.public.dotnet.framework.aspnet)
    • Re: SPAM Relay
      ... Please post the resolution to ... email replies from destinations sent from my domain. ... Here are some articles about checking for relay, ... setup to relay unless your administrator specifically changed the ...
      (microsoft.public.windows.server.sbs)
    • Re: Store.exe taking 100% CPU usage:Urgent
      ... I tried stopping the smtp service .And my cpu usage became ... normal .However the setting of relay is okay.Can u suggest ... Bacic authenication is checked ...
      (microsoft.public.exchange2000.information.store)
    • Re: Relaying denied after changing gateway ip
      ... Exchange server to relay SMTP through? ... I will lay odds that you have a relay configuration on your Exchange ... Make sure you stop/start the smtp service afterwards. ...
      (microsoft.public.exchange2000.admin)
    • Re: E-mail help(That helped)
      ... > valid credentials to logon to the SMTP service, so it will be denied to ... > to allow a specific IP (the IP of the machine running the application) to ... > allowed to relay. ... >> I have an asp.net web application that should send password reminder for ...
      (microsoft.public.windows.server.general)