New Microsoft Exchange Server Vulnerability

From: Paul Kurczaba (paul_at_myipis.com)
Date: 11/15/03

  • Next message: nmindell_at_microsoft.com: "Webcast: Microsoft Security VP talks about what Microsoft is doing about security"
    To: "'Tom Burns'" <tburns@torcausa.com>, <focus-ms@securityfocus.com>, <security-basics@securityfocus.com>
    Date: Fri, 14 Nov 2003 22:32:23 -0500
    
    

    Here is a link that I ran across. There is a new flaw that allows spammers
    to send emails through Microsoft Exchange.

    http://zdnet.com.com/2100-1105_2-5107904.html?tag=zdfd.newsfeed

    -Paul Kurczaba

    -----Original Message-----
    From: Tom Burns [mailto:tburns@torcausa.com]
    Sent: Tuesday, November 11, 2003 9:00 AM
    To: focus-ms@securityfocus.com
    Subject: Exchange SMTP Hole?

    Good morning all,

    I have an exchange server that's been running for quite some time (over a
    year) and had it locked down to prevent relay (spam). It is patched all the
    way up to 3a.

    I checked my queues yesterday and got slammed by spam relaying.

    Is there a security hole that MS does not know about yet in SMTP?????

    The only way I resolved this was to block connection from 219.x.x.x,
    218.x.x.x, 211.x.x.x, etc.

    This server has been testing aginst ORDB.ORG and shown to NOT be an open
    relay.

    If anyone has any suggestions, please let me know.

    Thomas A. Burns
    System Administrator
    Torca Products Inc.
    Auburn Hills, MI 48326
    248-373-8300 x186

    ---------------------------------------------------------------------------
    Network with over 10,000 of the brightest minds in information security at
    the largest, most highly-anticipated industry event of the year. Don't miss
    RSA Conference 2004! Choose from over 200 class sessions and see demos from
    more than 250 industry vendors. If your job touches security, you need to be
    here. Learn more or register at
    http://www.securityfocus.com/sponsor/RSA_focus-ms_031027
    and use priority code SF4.
    ---------------------------------------------------------------------------

    ---------------------------------------------------------------------------
    Network with over 10,000 of the brightest minds in information security
    at the largest, most highly-anticipated industry event of the year.
    Don't miss RSA Conference 2004! Choose from over 200 class sessions and
    see demos from more than 250 industry vendors. If your job touches
    security, you need to be here. Learn more or register at
    http://www.securityfocus.com/sponsor/RSA_focus-ms_031027
    and use priority code SF4.
    ---------------------------------------------------------------------------


  • Next message: nmindell_at_microsoft.com: "Webcast: Microsoft Security VP talks about what Microsoft is doing about security"

    Relevant Pages

    • Re: Exchange SMTP Hole?
      ... By default Exchange allows relaying for authorized users. ... | Is there a security hole that MS does not know about yet in SMTP????? ... most highly-anticipated industry event of the year. ...
      (Focus-Microsoft)
    • Re: CEH and Intense School
      ... > You want more than 4 to know the bugs are ironed out in labs and so on. ... > Network with over 10,000 of the brightest minds in information security ... most highly-anticipated industry event of the year. ...
      (Pen-Test)
    • Re: Convincing the boss to move to Exchange
      ... Trend CMS for SMB will not with Symantec in place ... I can't get the Mail Security Suite from Techsoup. ... Will Trend for Exchange work with Symantec Corporate AV? ...
      (microsoft.public.windows.server.sbs)
    • RE: help with exchange
      ... "the information store Stop responding, and the CPU usage level remains at 100 percent" and I them read and aply all the steps describe in Microsft Knowledge Base Article 31384, and still I can not read my mail. ... Subject: help with exchange ... Security Linux, the comprehensive security solution that combines six ...
      (Security-Basics)
    • Microsoft Exchange Server Product Support Bulletin
      ... Got this in an email from Microsoft PSS today and thought I would share it ... As part of our commitment to help customers improve and maintain security, ... you of some Exchange security best practices that you can use to improve ... / 2003 Server, and may also generate -1018 errors. ...
      (microsoft.public.backoffice.smallbiz2000)