Re: Security issue with MS Exchange and Windows 2003 Server

From: David H. Lipman (DLipman~nospam~_at_Verizon.Net)
Date: 11/28/05

  • Next message: vcast: "Re: locate.exe"
    Date: Mon, 28 Nov 2005 17:32:26 -0500
    
    

    From: "ITTester" <ITTester@discussions.microsoft.com>

    | I have posted this message on Exchange Newsgroup but is seem that nobody is
    | able to help me so I post it again in this newsgroup hopping someone can help
    | me.
    |
    | Can anyone help me for the below points
    |
    | General overview of the problem:
    | We have a single Exchange Server running on an DC and AD server
    | During the past month, our server is infected with hackdef which open
    | backdoor on our firewall (cisco pix 506e) and to our networks.
    | However we have patched the security hole by remote (ssh) on the firewall
    | and we are able to secure partially the network.
    | We have rebuilt the DC and AD server using promote an depromote method - We
    | have successfully added the second DC to our network but not yet promote this
    | box to be the primary DC as we are not sure about the mailboxes moving.
    | We have successfully configured a second mail server ready for the moving of
    | mailboxes
    | We have mount the new mail server offline and updated all security patches
    | (Windows server SP1 and Exchange SP2)
    | We use temporally an different AntiVirus which a not controlled by the DC
    | for safety reason.
    | We have successfully test the moving of a single mailbox
    | It seem that everything are ready for the final move.
    | However we are concerned for the below points:
    |
    | 1. Can hackdef or its variants infect the new mail servers by moving the
    | mailboxes?
    | 2. Can data on the moved mailboxes infect the new server - we have one
    | user's mailboxes which is infected by a virus / trojan
    |
    | Do we need to rebuilt from scratch if the above point are not safe.
    | We can't perform a anti-virus scan on the exchange db before the move as db
    | will be corrupted so it's not usefull.
    | Please advise if there any other alternative for this matter.
    |
    | Regards,
    |

    What anti virus software are you using that is specifically designed to run on a MS Exchange
    Server ?

    You said "Can hackdef or its variants..." Is that really the FULL name of this infector ?
    Knowing what the AV software that detected the infector would help.

    -- 
    Dave
    http://www.claymania.com/removal-trojan-adware.html
    http://www.ik-cs.com/got-a-virus.htm
    

  • Next message: vcast: "Re: locate.exe"

    Relevant Pages

    • RE: Single Server Upgrade Exchange Question
      ... The Exchange Migration Wizard can migrate all user mailboxes. ... server and then import them to the destination server. ... Single Server Upgrade Exchange Question ...
      (microsoft.public.windows.server.sbs)
    • Re: no mailboxs in private foulder
      ... limited experince with exchange. ... Ping the exchange server ... Right click the mailbox store, is the first option "mount store" or is it ... Where are you seeing "Mailboxes and stuff"? ...
      (microsoft.public.exchange.admin)
    • Re: ADC Tool Step 3 - Resource Mailbox Wizard
      ... The resource mailboxes are still going to be replicated ... > will still exist on Exchange 5.5 server, ... I think of the AD as Exchange 2K3's ...
      (microsoft.public.exchange.setup)
    • RE: is there a windows or exchange equivalent of fetchmail?
      ... SBC email account and put it on a local exchange mailbox. ... In SBS Server, we can use the POP3 Connector to ... retrieve incoming email from ISP POP3 mailboxes. ...
      (microsoft.public.windows.server.sbs)
    • Re: ADC Tool Step 3 - Resource Mailbox Wizard
      ... The resource mailboxes are still going to be replicated ... > will still exist on Exchange 5.5 server, ... I think of the AD as Exchange 2K3's ...
      (microsoft.public.exchange2000.setup.installation)