Re: Security issue with MS Exchange and Windows 2003 Server

From: Leythos (void_at_nowhere.lan)
Date: 11/28/05


Date: Mon, 28 Nov 2005 22:53:42 GMT

In article <820A8F04-BA76-40CD-B07F-718CAB32B830@microsoft.com>,
ITTester@discussions.microsoft.com says...
> 1. Can hackdef or its variants infect the new mail servers by moving the
> mailboxes?
> 2. Can data on the moved mailboxes infect the new server - we have one
> user's mailboxes which is infected by a virus / trojan
>
> Do we need to rebuilt from scratch if the above point are not safe.
> We can't perform a anti-virus scan on the exchange db before the move as db
> will be corrupted so it's not usefull.
> Please advise if there any other alternative for this matter.

Anything you move to the new server that COULD contain a virus (like
your mail stores, or PST files if you exported them) could still contain
the virus and still be executed by users at any time.

Why are you not running Exchange aware SMTP based AV software?

Why are you not removing attachments BEFORE they reach the Exchange
store - if your firewall doesn't do this in an SMTP Proxy service, your
Exchange SMTP session aware AV software should be able to do it.

You can run all the malware removal tools you want, but if the malware
is in the store you don't have much hope.

If I were in your place I would do the following:

Setup a new server, install Symantec Corporate Edition 10.0 and properly
update it, then set the proper file/folder/extension exclusions based on
MS and Symantec's recommendations, then I would install Symantec Mail
Security 4.6 and update it, then import the mail boxes, and then run a
manual scan on them from inside Symantec Mail Security.

Once that's done I would setup SMS 4.6 to remove attachments that could
contain malware and also use it for spam filtering.

-- 
spam999free@rrohio.com
remove 999 in order to email me


Relevant Pages

  • RE: Single Server Upgrade Exchange Question
    ... The Exchange Migration Wizard can migrate all user mailboxes. ... server and then import them to the destination server. ... Single Server Upgrade Exchange Question ...
    (microsoft.public.windows.server.sbs)
  • Re: no mailboxs in private foulder
    ... limited experince with exchange. ... Ping the exchange server ... Right click the mailbox store, is the first option "mount store" or is it ... Where are you seeing "Mailboxes and stuff"? ...
    (microsoft.public.exchange.admin)
  • Re: ADC Tool Step 3 - Resource Mailbox Wizard
    ... The resource mailboxes are still going to be replicated ... > will still exist on Exchange 5.5 server, ... I think of the AD as Exchange 2K3's ...
    (microsoft.public.exchange.setup)
  • RE: is there a windows or exchange equivalent of fetchmail?
    ... SBC email account and put it on a local exchange mailbox. ... In SBS Server, we can use the POP3 Connector to ... retrieve incoming email from ISP POP3 mailboxes. ...
    (microsoft.public.windows.server.sbs)
  • Re: ADC Tool Step 3 - Resource Mailbox Wizard
    ... The resource mailboxes are still going to be replicated ... > will still exist on Exchange 5.5 server, ... I think of the AD as Exchange 2K3's ...
    (microsoft.public.exchange2000.setup.installation)