[x]
Posted via EE Mobile

Search, ask, and monitor your questions on the go with EE Mobile. Visit Experts Exchange from your mobile device and never be out of touch again.

07/26/2007 at 11:28AM PDT, ID: 22723595
[x]
Attachment Details
[x]
The Solution Rating System

With so many solutions, how can you tell which solutions are most likely to help you and which ones are not? To provide you with a tool to use, we rate our solutions based on various elements that most accurately determine if a solution is a quality solution. To explain what factors affect the solution rating, here are the elements we take into consideration when formulating our solution rating.

  • The Grade of the Solution
  • The Zone Rank of the Expert Providing the Solution
  • The Number of Author and Expert Comments
  • The Number of Experts Contributing
  • The Feedback of the Community

Your Input Matters
Because of the way the system is set up, the most important variable in this equation is you. As a member of Experts Exchange, you are able to cast your vote on the quality of the solutions in regard to how complete, accurate, helpful and easy to understand each solution is. When you provide your feedback, each rating is adjusted accordingly. So, if you see a solution that has a poor rating that you think is a good solution, let us know by rating it. As you do, the rating will be adjusted and will become more accurate for other members of our site.

If you have any suggestions that you would like to make for our rating system, please ask a question in the Suggestions Zone of Community Support.

Thank you!

6.6

Finding the source of Very High In-Bound Internet Usage - Possible attack on ISA/Exchange Server

Asked by PeteJH in MS Forefront-ISA, SBS Small Business Server, Network Software Firewalls

Tags: internet, usage, 2003

Hi Everyone,

I have an Internet Security related question that I need help with. The environment is as follows:

- CISCO PIX Hardware Firewall (running NAT) - Port 25 forwarded to internal mail server (the server below).
- Windows Small Business Server 2003 Premium Edition with ISA 2004 (also runs NAT). This server also runs Exchange 2003 Server running email and collect mail that the PIX forwards through on port 25.

All of a sudden my client's Internet usage has blown out to over 40Gb a month (it was previouly averaging 15Gb). This is a very expensive problem as their ISP charges a ridiculous amount for the extra usage. I have investigated this thouroughly and know the following:

- The damage is done in the space of 4 or 5 days, with all other days experiencing normal Internet usage levels. Download usage will average at about 5Gb per day during this time (it's only a smallish site with 25 users, so that is a lot).

- The ISA 2004 Logs and Internet Access Monitor Plug-in (a program that checks the ISA logs for bandwidth usage) show that the traffic of concern is in-bound (download) and all SMTP (Port 25). Uploads are not a concern.

- ISA Logs and Internet Access Monitor Plug-in both confirm that all the traffic is coming from the IP of my ISP's Antivirus/Antispam filtering system. The system is configured such that all mail passes through the ISPs filtering service before reaching the in-house Exchange Server.

- I have checked with the ISP and they have checked the logs on their filtering servers and claim that the data was not sent from them (could the IP have been spoofed?).

- I have installed Ethereal Packet sniffer to the server and looked at the packets. I have confirmed that the packets are SMTP, and coming from the ISP's filtering server IP. I am not overly familiar with Ethereal, so am not able to interpret the packets overly well (apart from the basic info they provide).

- I have checked the ISPs daily reports and confirmed all the download usage levels to confirm everything I have said above seems to fit.

- When the SMTP traffic is being sent, there is no sign of any emails reaching the Exchange Server (and no NDRs are being sent etc). I have made sure of this - it is 4am here (I'm working around the clock) and only 3 emails have come into the Exchange Server since midnight. However the Internet Usage has been going mad all night, and if I start capturing packets with Ethereal, soon enough packets will come through on port 25 from that same IP.

I have no idea what the problem is, but can only assume it is some sort of attack. I need someone to give me some ideas as to what the attack might be and what I might be able to do about it. This cost my client a lot of money on last month's internet bill and this month is headed to the same result.

I will appreaciate any comments given.

Thanks
Pete
[+][-]07/26/07 11:37 AM, ID: 19577009

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07/26/07 11:54 AM, ID: 19577158

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07/26/07 11:58 AM, ID: 19577191

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07/26/07 11:59 AM, ID: 19577206

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07/26/07 07:08 PM, ID: 19579808

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]07/26/07 07:55 PM, ID: 19579981

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]07/26/07 10:35 PM, ID: 19580399

View this solution now by starting your 30-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: MS Forefront-ISA, SBS Small Business Server, Network Software Firewalls
Tags: internet, usage, 2003
Sign Up Now!
Solution Provided By: keith_alabaster
Participating Experts: 3
Solution Grade: A
 
 
[+][-]07/26/07 10:51 PM, ID: 19580449

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]07/26/07 11:05 PM, ID: 19580479

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07/27/07 12:14 AM, ID: 19580655

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]07/27/07 01:23 AM, ID: 19580876

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]07/28/07 12:40 AM, ID: 19583929

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07/28/07 01:58 AM, ID: 19584050

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07/28/07 02:01 AM, ID: 19584055

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07/28/07 06:53 AM, ID: 19584671

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]07/28/07 09:50 AM, ID: 19585226

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07/28/07 01:21 PM, ID: 19585922

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07/28/07 02:35 PM, ID: 19586129

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07/29/07 10:26 PM, ID: 19590271

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]07/30/07 03:50 AM, ID: 19591403

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07/30/07 10:55 AM, ID: 19594344

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07/30/07 08:44 PM, ID: 19597641

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]07/30/07 11:25 PM, ID: 19598107

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
 
Loading Advertisement...
20091111-EE-VQP-91