Solved

Filter recipients who are not in the Directory

Posted on 2011-09-20
2
275 Views
Last Modified: 2012-05-12
Hello,

I have this setting enabled "Filter recipients who are not in the Directory" in our Exchange Server 2003. However, our consulting company has advised to remove this setting to prevent hackers from farming for valid e-mail addresses. Any thoughts on this? Do you guys leave this setting on or off and why? Thanks!
0
Comment
Question by:vrosas_03
2 Comments
 
LVL 1

Accepted Solution

by:
TPAMisfit earned 500 total points
ID: 36570672
I think Microsoft recommends not enabling this feature because once you do, a Directory Harvest Attack can be used to gain knowledge of the valid e-mail addresses in your organization. Personally, we have it enabled and use the Tar pit KB to help difuse any attacks.

See MS article:

After you enable recipient filtering, a certain technique may be used against your Exchange server to gather information about the valid e-mail addresses in your organization. This technique is known as a Directory Harvest Attack.

For more information about how to help prevent this kind of attack, click the following article number to view the article in the Microsoft Knowledge Base:
 842851  SMTP tar pit feature for Windows Server 2003
0
 

Author Closing Comment

by:vrosas_03
ID: 36594049
Thanks. I guess I'll have to remove on my end for security.

0

Featured Post

Free book by J.Peter Bruzzese, Microsoft MVP

Are you using Office 365? Trying to set up email signatures but you’re struggling with transport rules and connectors? Let renowned Microsoft MVP J.Peter Bruzzese show you how in this exclusive e-book on Office 365 email signatures. Better yet, it’s free!

Join & Write a Comment

We are happy to announce a brand new addition to our line of acclaimed email signature management products – CodeTwo Email Signatures for Office 365.
Find out what Office 365 Transport Rules are, how they work and their limitations managing Office 365 signatures.
In this video we show how to create a Contact in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Contact ta…
In this video we show how to create a mailbox database in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Servers >> Data…

706 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now