?
Solved

Spam emails filling up Exchange 2003 Queue

Posted on 2012-04-03
10
Medium Priority
?
654 Views
Last Modified: 2012-04-04
All

I'm at my wits end.  I have a sbs 2003 with exchange and the queue seem to be constantly filling up.  I scanned pcs and servers with Malware Bytes, combofix, and Symantec.  Under the default virtual server I see some connections under the [current status].  These ips are known to be bad.  I terminate them but them come back after a while.  I need some program to trace where these are coming from.  I even shutdown every pc except the server and a couple other critical pcs.

help
0
Comment
Question by:jacobb_2000
  • 3
  • 2
  • 2
  • +2
9 Comments
 
LVL 76

Accepted Solution

by:
Alan Hardisty earned 2000 total points
ID: 37803481
My article discusses an Authenticated Relay situation (as well as an NDR attack) and due to the volume of Authenticated relay Attacks I have seen of late, I would suspect that this is what is happening.

Please have a read of my article and work through the logging level increase to isolate the account.

http://www.experts-exchange.com/Software/Server_Software/Email_Servers/Exchange/A_2556-Why-are-my-outbound-queues-filling-up-with-mail-I-didn't-send.html

Also - please have a read of my two blog articles:

http://alanhardisty.wordpress.com/2010/09/28/increase-in-frequency-of-security-alerts-on-servers-from-hackers-trying-brute-force-password-programs/

http://alanhardisty.wordpress.com/2010/12/01/increase-in-hacker-attempts-on-windows-exchange-servers-one-way-to-slow-them-down/

The last blog entry has a quick fix which should stop the problem dead in it's tracks.

Alan
0
 
LVL 12

Expert Comment

by:Pradeep
ID: 37803500
Enable IMF settings and create a new Virtual SMTP server, rename the queue and restart the Smtp service.
0
 
LVL 9

Expert Comment

by:Geodash
ID: 37803504
I had this happen to a client. We put them on MXLogic, tightened their firewall down to not accept or send ANY mail inbound or outbound unless it goes through MXLogic, it went away immediately.

It will take a long time to blacklist the IP ranges from China and Korea in your firewall.
0
Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

 
LVL 12

Expert Comment

by:DLeaver
ID: 37803576
One way of stopping this when I have had this issue is adjusting the SMTP authentication/relay settings as I posted in this previous post here

http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Server/SBS_Small_Business_Server/Q_27606804.html

This won't empty your queues once they are full but it should stop Exchange from getting full of SPAM once you have empted them- nice and simple
0
 
LVL 9

Expert Comment

by:Geodash
ID: 37803591
What happened to a previous client of mine was they put the wrong setting somewhere in Exchange, I don't remember where, which allowed their server to be a relay from the web with some vulnerability on the server, Microsoft has patched it since. We fixed it and locked EVERYTHING down through MXLogic and the Sonicwall now absolutely nothing gets through.

There Queue was filling up with over 200,000k SPAM messages a day
0
 

Author Comment

by:jacobb_2000
ID: 37803642
Alan

I removed basic and integrated auth.  so far so good. let me give it a day or two and will give you the points if that solves the issues.
thx

Jake
0
 
LVL 9

Expert Comment

by:Geodash
ID: 37803649
So removing basic and integrated auth, if a spammer out there is still sending say 2,000 mails per hour to your server, your server is still processing them, just not letting them through. There is still overhead and bandwidth and latency and everything else. I hope it fixes the issue.
0
 

Author Comment

by:jacobb_2000
ID: 37807373
Alan

so far all looking good.
thanks a lot.

I will give you all the points

jake
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 37807388
Thanks Jake - glad your problem is sorted and thanks for the points.

Alan
0

Featured Post

Simplify Active Directory Administration

Administration of Active Directory does not have to be hard.  Too often what should be a simple task is made more difficult than it needs to be.The solution?  Hyena from SystemTools Software.  With ease-of-use as well as powerful importing and bulk updating capabilities.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

This is a very interesting topic. Ransomware has been around for a while but has increased drastically over the last year or so.
Microsoft Exchange Server gives you the ability to roll back a corrupt database, but still preserve any data written to that database since the last successful backup. Unfortunately the documentation on how to do this when recovering using imaging b…
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…
To export Lotus Notes to Outlook PST or Exchange and Domino Server files to Exchange Server or PST files with ease, go for Kernel for Lotus Notes to Outlook conversion tool. Through the video, you can watch the conversion process. A common user with…

589 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question