?
Solved

Exchange sending SPAM

Posted on 2004-03-29
9
Medium Priority
?
495 Views
Last Modified: 2010-03-05
Im running Exchange 2000 server. The mail queue keeps filling up with spam. Relay is not open. Guest account is disabled.

I even removed it from the network, and the queue continues to fill up. Have done a complete AV scan and nothing.

Also if i do find the problem, is there an easy way to clean the queue?


Please help.
0
Comment
Question by:joh2900
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
9 Comments
 
LVL 10

Accepted Solution

by:
OneHump earned 200 total points
ID: 10710307
There is something spammers do called a dictionary harvest attack.  It's common and Exchange is a weak SMTP perimeter server so there is little you can do within Exchange to prevent it.

What happens is address list harvesters run through the dictionary @yourdomain.com and count up rcpt to: commands that are accepted.  The result is a queue full of spam and a badmail folder full of messages that couldnt be returned because they send from an invalid address.

Your best bet is to deploy a better perimeter solution in front of your Exchange server.  Tumbleweed, Trend, Ironport, ChipherTrust and Postini all have decent solutoins.  There are many others as well.

OneHump
0
 

Author Comment

by:joh2900
ID: 10710435
its offline and still queing mail.??
0
 
LVL 5

Assisted Solution

by:visioneer
visioneer earned 200 total points
ID: 10710468
Exchange seems to be prone to attacks based on the authentication methods on the SMTP server.  You should check the properties of the Default SMTP Virtual Server, go to the Access tab, click Relay, and UN-check the box that reads "Allow all computers which successfully authenticate to relay, regardless of the list above."  Let us know if that makes the spam subside.
0
Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

 

Author Comment

by:joh2900
ID: 10710520
changing authentication didnt help..... It almost seems as if somethings creating the emails from within that server... The server isnt even plugged into the network.

Have done a comlete scan with 2 different engines and both come up blank..
0
 
LVL 24

Expert Comment

by:David Wilhoit
ID: 10710934
unplugging the server won't make this go away, those queues need to be emptied out manually.

d
0
 
LVL 10

Expert Comment

by:OneHump
ID: 10713987
Email is not queing whent he server is offline.  What is happening is that email is being processed through your queues.  You won't always see them in ESM even though they are there.  There is a resource kit tool called MailQ you can use to get a better view of your queues.

Nothing with authentication, nothing with an open relay; This is a textbook dictionary attack.

OneHump
0
 
LVL 10

Expert Comment

by:OneHump
ID: 10815360
Where are we at with this?

OneHump
0

Featured Post

Free Backup Tool for VMware and Hyper-V

Restore full virtual machine or individual guest files from 19 common file systems directly from the backup file. Schedule VM backups with PowerShell scripts. Set desired time, lean back and let the script to notify you via email upon completion.  

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A couple of months ago we ran into an issue that necessitated re-creating our Edge Subscriptions. However, when we attempted to execute the command: New-EdgeSubscription -filename C:\NewEdgeSub_01.xml we received an error indicating that the LDAP se…
New style of hardware planning for Microsoft Exchange server.
This video demonstrates how to sync Microsoft Exchange Public Folders with smartphones using CodeTwo Exchange Sync and Exchange ActiveSync. To learn more about CodeTwo Exchange Sync and download the free trial, go to: http://www.codetwo.com/excha…
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…
Suggested Courses

741 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question