Re: Exchange 2000

From: Andrew Mitchell (amitchel_at_removecasey.vic.gov.au)
Date: 03/16/04


Date: Tue, 16 Mar 2004 02:31:37 -0800


"Sam Ramsey" <anonymous@discussions.microsoft.com> said

> I have Exchange 2000 with all the latest patches and IIS
> lockdown loaded. I also have a Cisco PIX firewall with
> only port 25 and 80 available on the outside ip address of
> the exchange box.
>
> I just loaded a web monitoring software for our network
> and noticed that exchange box is going to porn web sites
> all day long. I thought it might be monitoring email
> traffic, but that is not case. I assuming some hacker is
> exploiting a vulnerability in Exchange 2000. Possibly IIS
> and port 80 or 25? Is there anything I do about this?

Why is the exchange/IIS server being allowed out on port 80 in the first
place? It has no need for web access and should be blocked at the firewall.
Firewalls aren't just usefull for keeping the baddies out, they are also
useful for stopping stuff escaping your network that has no need to.
Setup a web proxy (with authentication) and only allow traffic from the
proxy server IP out through the firewall on port 80.

Regards
Andy.



Relevant Pages

  • Re: Unable to Receive Email from the internet
    ... Are you running this on Longhorn server? ... Test from outside your firewall: ... Exchange Server 2007: internet email without Edge ... looking at the firewall inbound rules on my LHS. ...
    (microsoft.public.exchange.setup)
  • Re: Exchange server behind firewall cant send outgoing
    ... > I am having some problems with a firewall, and specifically the Exchange ... > non-local users email to the Exchange server. ... Depending on the DNS servers of your ISP. ...
    (comp.security.firewalls)
  • RE: Exchange 2003
    ... This behavior seems plausible if there's a stateful firewall in the ... the case, then clearly, you won't get anything back from an nbtstat, ... does it allow it after there's a connection?". ... without exchange 2003 on it. ...
    (Pen-Test)
  • Re: SELF Attribute not updating through firewall
    ... Testing server: LEGAL\subdomaindc ... Exchange Server. ... The users access their email from behind the firewall. ... subdomain, as their is only a single Exchange server on the whole Forest, ...
    (microsoft.public.exchange.admin)
  • Exchange server behind firewall cant send outgoing
    ... I am having some problems with a firewall, and specifically the Exchange ... Our ISP manages DNS for us - the MX record is set to the firewall. ... Then sendmail would send it, ...
    (comp.security.firewalls)