Solved

Spam emails filling up Exchange 2003 Queue

Posted on 2012-04-03
10
643 Views
Last Modified: 2012-04-04
All

I'm at my wits end.  I have a sbs 2003 with exchange and the queue seem to be constantly filling up.  I scanned pcs and servers with Malware Bytes, combofix, and Symantec.  Under the default virtual server I see some connections under the [current status].  These ips are known to be bad.  I terminate them but them come back after a while.  I need some program to trace where these are coming from.  I even shutdown every pc except the server and a couple other critical pcs.

help
0
Comment
Question by:jacobb_2000
  • 3
  • 2
  • 2
  • +2
10 Comments
 
LVL 76

Accepted Solution

by:
Alan Hardisty earned 500 total points
ID: 37803481
My article discusses an Authenticated Relay situation (as well as an NDR attack) and due to the volume of Authenticated relay Attacks I have seen of late, I would suspect that this is what is happening.

Please have a read of my article and work through the logging level increase to isolate the account.

http://www.experts-exchange.com/Software/Server_Software/Email_Servers/Exchange/A_2556-Why-are-my-outbound-queues-filling-up-with-mail-I-didn't-send.html

Also - please have a read of my two blog articles:

http://alanhardisty.wordpress.com/2010/09/28/increase-in-frequency-of-security-alerts-on-servers-from-hackers-trying-brute-force-password-programs/

http://alanhardisty.wordpress.com/2010/12/01/increase-in-hacker-attempts-on-windows-exchange-servers-one-way-to-slow-them-down/

The last blog entry has a quick fix which should stop the problem dead in it's tracks.

Alan
0
 
LVL 12

Expert Comment

by:Deepu Chowdary
ID: 37803500
Enable IMF settings and create a new Virtual SMTP server, rename the queue and restart the Smtp service.
0
 
LVL 9

Expert Comment

by:Geodash
ID: 37803504
I had this happen to a client. We put them on MXLogic, tightened their firewall down to not accept or send ANY mail inbound or outbound unless it goes through MXLogic, it went away immediately.

It will take a long time to blacklist the IP ranges from China and Korea in your firewall.
0
 
LVL 12

Expert Comment

by:DLeaver
ID: 37803576
One way of stopping this when I have had this issue is adjusting the SMTP authentication/relay settings as I posted in this previous post here

http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Server/SBS_Small_Business_Server/Q_27606804.html

This won't empty your queues once they are full but it should stop Exchange from getting full of SPAM once you have empted them- nice and simple
0
Being driven mad by email signature updates?

Having to make a change to your users’ email signatures, yet again? Feel like your head is going to explode? Rely on an Exclaimer email signature management solution to make the process simple!

 
LVL 9

Expert Comment

by:Geodash
ID: 37803591
What happened to a previous client of mine was they put the wrong setting somewhere in Exchange, I don't remember where, which allowed their server to be a relay from the web with some vulnerability on the server, Microsoft has patched it since. We fixed it and locked EVERYTHING down through MXLogic and the Sonicwall now absolutely nothing gets through.

There Queue was filling up with over 200,000k SPAM messages a day
0
 

Author Comment

by:jacobb_2000
ID: 37803642
Alan

I removed basic and integrated auth.  so far so good. let me give it a day or two and will give you the points if that solves the issues.
thx

Jake
0
 
LVL 9

Expert Comment

by:Geodash
ID: 37803649
So removing basic and integrated auth, if a spammer out there is still sending say 2,000 mails per hour to your server, your server is still processing them, just not letting them through. There is still overhead and bandwidth and latency and everything else. I hope it fixes the issue.
0
 

Author Comment

by:jacobb_2000
ID: 37807373
Alan

so far all looking good.
thanks a lot.

I will give you all the points

jake
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 37807388
Thanks Jake - glad your problem is sorted and thanks for the points.

Alan
0

Featured Post

[Webinar] Disaster Recovery and Cloud Management

Learn from Unigma and CloudBerry industry veterans which providers are best for certain use cases and how to lower cloud costs, how to grow your Managed Services practice in IaaS clouds, and how to utilize public cloud for Disaster Recovery

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Lotus Notes – formerly IBM Notes – is an email client application, while IBM Domino (earlier Lotus Domino) is an email server. The client possesses a set of features that are even more advanced as compared to that of Outlook. Likewise, IBM Domino is…
We are happy to announce a brand new addition to our line of acclaimed email signature management products – CodeTwo Email Signatures for Office 365.
In this video we show how to create an Address List in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Organization >> Ad…
In this video we show how to create an email address policy in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Mail Flow…

920 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now