As far as the NDR attack is concerned the email addresses are not being spoofed to be real sent froms. So could this still be a possiblity?
I do not believe that anyone is collecting email through OE.
Finally We are not using SBS, is there anyway to clean the queues within Exchange Server 2000?
Thanks,
Steve
Main Topics
Browse All Topics





by: SembeePosted on 2004-08-23 at 09:21:32ID: 11872062
Probably an NDR attack. This is where messages are sent to your server with a non valid email address on purpose and your machine bounces them back as NDRs. The From line has been spoofed to be the real recipient of the message.
om/default .aspx?kbid =324958
Disable NDRs in ESM which will stop more messages flowing out.
If it isn't that then it could be an authenticated SMTP relay. This is where a password on your system has been guessed and you are allowing SMTP traffic through. Do you have any one collecting email through Outlook Express and then sending through your server? If not, disable this feature as it isn't required.
Then take a look at this article from Microsoft on how to clean up: http://support.microsoft.c
Simon.