?
Solved

Exchange server NDR attack, need help resolving

Posted on 2011-05-05
13
Medium Priority
?
405 Views
Last Modified: 2012-05-11
I am fighting an NDR attack from the domain hinet.net. Our environment is small, with one Exchange 2003 server. I adjusted the server yesterday to close an open relay, and to enable recipient filtering/tarpitting due to an NDR attack. I've also disabled NDR'ing for now. However, the queues are still filling with NDR's and spam e-mails that pre-date the configuration changes I've made? What can I do to get the server operational again, and clear the queues?
0
Comment
Question by:Cdavis316
12 Comments
 
LVL 37

Expert Comment

by:Neil Russell
ID: 35698331
0
 
LVL 19

Expert Comment

by:Miguel Angel Perez Muñoz
ID: 35698359
Try blocking NDR´s, and deleting queues. This may help you: http://www.experts-exchange.com/Software/Server_Software/Email_Servers/Exchange/Q_21108443.html
Add a spf record to fight against email spoof: http://www.openspf.org/ this may help to abort futures attacks.
0
 
LVL 37

Expert Comment

by:Neil Russell
ID: 35698362
And read the whole section found here

Clean Up the Exchange Server's SMTP Queues  http://support.microsoft.com/kb/324958#6
0
Creating Active Directory Users from a Text File

If your organization has a need to mass-create AD user accounts, watch this video to see how its done without the need for scripting or other unnecessary complexities.

 

Author Comment

by:Cdavis316
ID: 35698378
Already blocked NDR's, and cleared queues with aqadmcli. My real concern is the queues still fill after cleared with outdated messages. I read somewhere that this is a notoriously common problems (queues inaccurate after spam ndr attack)
0
 
LVL 23

Expert Comment

by:Suliman Abu Kharroub
ID: 35698423
Block this domain on your firewall... then no traffic can reach your server from that doamin/ ip address
0
 

Author Comment

by:Cdavis316
ID: 35698427
Good idea sulimanw
0
 

Author Comment

by:Cdavis316
ID: 35698440
I actually need to block a TLD which I've read isn't possible with filtering. I'll block it at the sonicwall and see if things subside.
0
 
LVL 37

Expert Comment

by:Neil Russell
ID: 35698520
IF you have closed your open relay AND dissabled NDR generation then blocking ANY domain at any level will not change things.
0
 

Author Comment

by:Cdavis316
ID: 35698534
I'm 100% sure that we aren't running an open relay and that NDR generation is disabled. What's could be causing the queues to fill with back-dated e-mail?
0
 
LVL 37

Expert Comment

by:Neil Russell
ID: 35698943
Disasble your inbound connection to the server and watch the queues?
0
 

Accepted Solution

by:
Cdavis316 earned 0 total points
ID: 35702059
I ended up doing an MS support call. The queue issue required us to manually empty the queue from the program files\exchsrvr\ follder, and to add an RBL. That cleared everything up
0
 
LVL 74

Expert Comment

by:Glen Knight
ID: 37523989
This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.
0

Featured Post

 [eBook] Windows Nano Server

Download this FREE eBook and learn all you need to get started with Windows Nano Server, including deployment options, remote management
and troubleshooting tips and tricks

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

How to effectively resolve the number one email related issue received by helpdesks.
In this post, I will showcase the steps for how to create groups in Office 365. Office 365 groups allow for ease of flexibility and collaboration between staff members.
In this video we show how to create a mailbox database in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Servers >> Data…
To show how to create a transport rule in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Mail Flow >> Rules tab.:  To cr…
Suggested Courses

807 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question