Solved

Exchange server 2003 being used as a spam relay

Posted on 2012-12-20
6
472 Views
Last Modified: 2012-12-26
Hi

My client's Windows 2K Exchange 2003 sp3 is being used a a spam relay :

Received: from User ([184.61.168.250]) by mailhost.XXXXXXXXXX.com with
Microsoft SMTPSVC(5.0.2195.7381);
         Tue, 18 Dec 2012 20:36:39 +0100
From: "E-Mail  Technical Services"<support@hp.com>
Subject: IMPORTANT INFORMATION IN YOUR MAILBOX
Date: Tue, 18 Dec 2012 13:40:50 -0600
MIME-Version: 1.0
Content-Type: text/plain;
        charset="Windows-1251"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
Bcc:
Return-Path: support@hp.com
Message-ID: <EXCHANGE2KVp20N39x600000a56@mailhost.XXXXXXXXXX.com>
X-OriginalArrivalTime: 18 Dec 2012 19:36:40.0378 (UTC)
FILETIME=[007E41A0:01CDDD57]

Your mailbox is almost full.
20GB


Your Web-mail Quota Has Exceeded The Set Quota/Limit Which Is 20GB.
You Are Currently Running On 23GB Due To Hidden Files And Folder On
Your Mailbox.
Please Click the Link Below To Validate Your Mailbox And Increase Your Quota.
CLICK HERE: http://activatenow.nclidz.com/
you keep changing your password allowed Web Mail Services to work
on your quota limit.Failure To Click This Link And Validate Your Quota
May Result In Loss Of Important Information In Your Mailbox/Or Cause
Limited Access To It.
Thank you for your cooperation.
Web Mail Technical Services

There were over 50000 emails in the SMTP queue !
Apparently the destination email adresses are bad
because the Exchange diagnostics log is FULL or
5.4.0 errors (I had approx 2GB worth of these logged
errors).

Is this spam ? or maybe a type of DoS attack ?
The server was on its needs two days following the
beginning of this situation.

I don't understand how these got through though
because I have specified in the SMTP protocol
properties that only the local subnet is allowed
(192.168.1.0/24) is allowed to relay.

So far the only solution I have found was to stop the
SMTP service and delete the files in the mailroot
queue

I'll check the access-rules on the CISCO 831 config to
see if there's any holes through there.

thanks

yann

NB
This is a copy of the cisco config:
ip inspect name FWOUT tcp
ip inspect name FWOUT udp
ip inspect name FWOUT icmp
ip inspect name FWOUT ftp
ip inspect name FWOUT smtp
!
interface Ethernet0
 ip address 192.168.1.254 255.255.255.0
 ip access-group 122 out
 ip nat inside
 no cdp enable
!
interface Ethernet1
 ip address XXX.XXX.XXX.XXX 255.255.255.248
 ip nat outside
 ip inspect FWOUT out
 duplex auto
 no cdp enable
!
ip local pool DIAL-IN 192.168.201.10 192.168.201.230
ip nat inside source list 20 interface Ethernet1 overload
ip nat inside source static tcp 192.168.1.5 443 interface Ethernet1 443
ip nat inside source static tcp 192.168.1.5 110 interface Ethernet1 110
ip nat inside source static tcp 192.168.1.5 143 interface Ethernet1 143
ip nat inside source static tcp 192.168.1.5 25 interface Ethernet1 25
ip nat inside source static tcp 192.168.1.5 3389 interface Ethernet1 3389
ip nat inside source static tcp 192.168.1.5 80 interface Ethernet1 80
ip classless
ip route 0.0.0.0 0.0.0.0 XXX.XXX.XXX.XXX 10

no ip http server
no ip http secure-server
!
access-list 5 remark SNMP
access-list 5 permit XXX.XXX.XXX.XXX
access-list 5 permit XXX.XXX.XXX.XXX
access-list 10 permit XXX.XXX.XXX.XXX 0.0.0.255
access-list 10 deny   any
access-list 20 permit 192.168.1.0 0.0.0.255
access-list 20 deny   any
access-list 23 permit xxx.xxx.xxx.xxx
access-list 23 permit xxx.xxx.xxx.xxx
access-list 23 permit 192.168.0.0 0.0.255.255
access-list 102 remark Incoming traffic
access-list 102 permit tcp any any eq smtp
access-list 102 permit tcp any any eq pop3
access-list 102 permit tcp any any eq 143
access-list 102 permit tcp any any eq 3389
access-list 102 permit tcp any any eq 443
access-list 121 remark ANTISPOOFING
access-list 121 deny   ip 127.0.0.0 0.255.255.255 any log-input
access-list 121 deny   ip 10.0.0.0 0.255.255.255 any log-input
access-list 121 deny   ip 172.16.0.0 0.15.255.255 any log-input
access-list 121 deny   ip 192.168.0.0 0.0.255.255 any log-input
access-list 121 permit ip any any
access-list 122 permit ip any host 192.168.1.5
access-list 122 permit ip any host 192.168.1.213
access-list 122 permit ip any host 192.168.1.117
access-list 122 permit ip any host 192.168.1.116
access-list 122 permit ip any host 192.168.1.108
access-list 122 permit ip any host 192.168.1.121
access-list 122 permit ip any host 192.168.1.107
access-list 122 permit ip any host 192.168.1.101
access-list 122 permit ip any host 192.168.1.100
access-list 122 permit ip any host 192.168.1.106
access-list 122 permit ip any host 192.168.1.105
access-list 122 deny   ip 192.168.201.0 0.0.0.255 any
access-list 122 permit icmp any any
access-list 122 permit ip any any
access-list 122 permit ip any host 192.168.1.251
0
Comment
Question by:Yann Shukor
  • 4
  • 2
6 Comments
 
LVL 7

Expert Comment

by:rsimsee
ID: 38711429
It's hard to t/s from here because I don't know your ip's or anything, but make sure you check the SMTP "server" and not just the smtp connector.  There is an option under the SMTP server properties (under protocals) called Relay under Access that controls who can relay.

It's a good idea to do an open relay test on your server, that will verify whether it is truely open or not.  I generally do them by hand with Telnet, but if you don't know how to do that there are a variety of sites that will do it for you such as this one:

http://www.mailradar.com/openrelay/
0
 

Author Comment

by:Yann Shukor
ID: 38712110
thanks rsimsee
I did specify that only the local subnet can relay messages through the SMTP server
We don't use an SMTP connector

I tried the openrelay test you suggested and all 18
methods passed except for test 7, 8 and 14
I'll look more deeply into why those three didn't pass

thanks
0
 

Author Comment

by:Yann Shukor
ID: 38712480
Apparently this is the result of an Reverse NDR attack
I'll let you know which solution I used to fix our situation
0
What Is Threat Intelligence?

Threat intelligence is often discussed, but rarely understood. Starting with a precise definition, along with clear business goals, is essential.

 
LVL 7

Expert Comment

by:rsimsee
ID: 38712978
Just an fyi, I just tested a client of mine with 2003 and all tests passed, so it must be something on your end.

Looking at the tests that you failed, I see that all of them have a "user unknown" response sent back from the server (at least on my server).  I know that have Exchange set to drop all mail not addressed to somebody in my organization, do you have that set?
0
 

Accepted Solution

by:
Yann Shukor earned 0 total points
ID: 38713093
thanks for that RSIMSEE

Well, I fixed the issue by implementing the recipient filtering option aswell as the SMTP tar pit registry modification :  
http://support.microsoft.com/kb/886208
http://support.microsoft.com/kb/842851

And now when I run the openrelay test, no more errors !
 
Phew, I'm glad that that's over !

thanks
0
 

Author Closing Comment

by:Yann Shukor
ID: 38720899
.
0

Featured Post

Free Trending Threat Insights Every Day

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

Pegasus Mail (http://www.pmail.com/) is a donation ware that is a collaboration of David Harris along with his team members. It is a desktop mail client that offers the option of configuring more than one mail account with single set up. It supports…
Find out what Office 365 Transport Rules are, how they work and their limitations managing Office 365 signatures.
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
This video shows how to remove a single email address from the Outlook 2010 Auto Suggestion memory. NOTE: For Outlook 2016 and 2013 perform the exact same steps. Open a new email: Click the New email button in Outlook. Start typing the address: …

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now