?
Solved

Spam emails filling up Exchange 2003 Queue

Posted on 2012-04-03
10
Medium Priority
?
649 Views
Last Modified: 2012-04-04
All

I'm at my wits end.  I have a sbs 2003 with exchange and the queue seem to be constantly filling up.  I scanned pcs and servers with Malware Bytes, combofix, and Symantec.  Under the default virtual server I see some connections under the [current status].  These ips are known to be bad.  I terminate them but them come back after a while.  I need some program to trace where these are coming from.  I even shutdown every pc except the server and a couple other critical pcs.

help
0
Comment
Question by:jacobb_2000
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
  • 2
  • +2
10 Comments
 
LVL 76

Accepted Solution

by:
Alan Hardisty earned 2000 total points
ID: 37803481
My article discusses an Authenticated Relay situation (as well as an NDR attack) and due to the volume of Authenticated relay Attacks I have seen of late, I would suspect that this is what is happening.

Please have a read of my article and work through the logging level increase to isolate the account.

http://www.experts-exchange.com/Software/Server_Software/Email_Servers/Exchange/A_2556-Why-are-my-outbound-queues-filling-up-with-mail-I-didn't-send.html

Also - please have a read of my two blog articles:

http://alanhardisty.wordpress.com/2010/09/28/increase-in-frequency-of-security-alerts-on-servers-from-hackers-trying-brute-force-password-programs/

http://alanhardisty.wordpress.com/2010/12/01/increase-in-hacker-attempts-on-windows-exchange-servers-one-way-to-slow-them-down/

The last blog entry has a quick fix which should stop the problem dead in it's tracks.

Alan
0
 
LVL 12

Expert Comment

by:Deepu Chowdary
ID: 37803500
Enable IMF settings and create a new Virtual SMTP server, rename the queue and restart the Smtp service.
0
 
LVL 9

Expert Comment

by:Geodash
ID: 37803504
I had this happen to a client. We put them on MXLogic, tightened their firewall down to not accept or send ANY mail inbound or outbound unless it goes through MXLogic, it went away immediately.

It will take a long time to blacklist the IP ranges from China and Korea in your firewall.
0
VIDEO: THE CONCERTO CLOUD FOR HEALTHCARE

Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

 
LVL 12

Expert Comment

by:DLeaver
ID: 37803576
One way of stopping this when I have had this issue is adjusting the SMTP authentication/relay settings as I posted in this previous post here

http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Server/SBS_Small_Business_Server/Q_27606804.html

This won't empty your queues once they are full but it should stop Exchange from getting full of SPAM once you have empted them- nice and simple
0
 
LVL 9

Expert Comment

by:Geodash
ID: 37803591
What happened to a previous client of mine was they put the wrong setting somewhere in Exchange, I don't remember where, which allowed their server to be a relay from the web with some vulnerability on the server, Microsoft has patched it since. We fixed it and locked EVERYTHING down through MXLogic and the Sonicwall now absolutely nothing gets through.

There Queue was filling up with over 200,000k SPAM messages a day
0
 

Author Comment

by:jacobb_2000
ID: 37803642
Alan

I removed basic and integrated auth.  so far so good. let me give it a day or two and will give you the points if that solves the issues.
thx

Jake
0
 
LVL 9

Expert Comment

by:Geodash
ID: 37803649
So removing basic and integrated auth, if a spammer out there is still sending say 2,000 mails per hour to your server, your server is still processing them, just not letting them through. There is still overhead and bandwidth and latency and everything else. I hope it fixes the issue.
0
 

Author Comment

by:jacobb_2000
ID: 37807373
Alan

so far all looking good.
thanks a lot.

I will give you all the points

jake
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 37807388
Thanks Jake - glad your problem is sorted and thanks for the points.

Alan
0

Featured Post

On Demand Webinar: Networking for the Cloud Era

Ready to improve network connectivity? Watch this webinar to learn how SD-WANs and a one-click instant connect tool can boost provisions, deployment, and management of your cloud connection.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Find out what you should include to make the best professional email signature for your organization.
A list of top three free exchange EDB viewers that helps the user to extract a mailbox from an unmounted .edb file and get a clear preview of all emails & other items with just a single click on mailboxes.
This video discusses moving either the default database or any database to a new volume.
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…
Suggested Courses

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question