Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

SmallBussines SMTP connector large queue with postmaster messages

Posted on 2013-11-06
5
Medium Priority
?
392 Views
Last Modified: 2013-11-06
spammer was authenticating with a hacked username against the Small Business Server computer as part of an operation to relay SMTP e-mail, causing an eventid 1708.
Changed account password already, no more emails from "something@something.com" coming out of our exchange.

but now on the "smallbusiness smtp connector queue there are thousands of messages from the postmaster@mydomain.com and it is not stopping, or at least is has been queuing for hours and submitting emails to the email that the spam was sending at.

Another detail is that we have a Mcafee offsite proxy where all our outbound emails go thru. They close the door of our affected ip address until we can tell them that we fix our problem.

I would like to stop the messages from the postmaster and clean the queues.

Thanks
0
Comment
Question by:75carlos
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
5 Comments
 
LVL 15

Accepted Solution

by:
Perarduaadastra earned 2000 total points
ID: 39626688
This is a common problem that has been addressed several times on EE.

The venerable expert alanhardisty has covered it here:

http://alanhardisty.wordpress.com/2010/02/11/why-are-my-outbound-queues-filling-up-with-mail-that-we-didnt-send/

... and Microsoft addresses the question here:

http://support.microsoft.com/kb/909005

These links should get you out of trouble.
0
 

Author Comment

by:75carlos
ID: 39626981
I'm done with the Authenticated Relay Attach securing process.
At one moment I saw like 60,000 messages on the queue so it will take aawhile to purge everything. I'm using the line command application aqadmcli.exe to speed up the process.

Two things I notice, the messages (Delivery status notification delay and failure)  from "postmaster" are still showing up...maybe are old and still popping up in the queue.....

the messages from the relay email account "membershipsrewards@membershipsrewards.com are still showing up in the SMTP connector but are old one...not sure when it going to end
0
 
LVL 15

Expert Comment

by:Perarduaadastra
ID: 39627002
If you look at Step 3 in the Microsoft KB, it explains that cleaning up the queues can be a lengthy process. If you have 60,000+ messages to get rid of then lengthy is probably an apt description...

Note that it may take some time before the total number of messages to be deleted becomes available.
0
 

Author Comment

by:75carlos
ID: 39627090
I've been turning on the computer and testing, everything up to now is fine but slow.
I'm cleaning by chunks , when it get to 4000 or 5000 I ran aqadmcli.exe using the delmsg flags=all since there is not user activity yet.
0
 
LVL 15

Expert Comment

by:Perarduaadastra
ID: 39627797
A way of speeding up the removal of messages is to stop the SMTP service and rename the Queue folder to something else, for example Badqueue. Then start the SMTP service again; this will generate a new Queue folder that will be empty. You can then delete the contents of the old renamed Queue folder (Badqueue in the example I gave) at your leisure.
Be very sure, however, that there is nothing important in that folder before deleting everything!

I've recently dealt with just such a situation, and it took about ten minutes for 80,000+ files to be deleted from the old renamed Queue folder, which is rather quicker than multiple passes with the aqadmcli utility.
0

Featured Post

Important Lessons on Recovering from Petya

In their most recent webinar, Skyport Systems explores ways to isolate and protect critical databases to keep the core of your company safe from harm.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Citrix XenApp, Internet Explorer 11 set to Enterprise Mode and using central hosted sites.xml file.
It’s been over a month into 2017, and there is already a sophisticated Gmail phishing email making it rounds. New techniques and tactics, have given hackers a way to authentically impersonate your contacts.How it Works The attack works by targeti…
Windows 8 comes with a dramatically different user interface known as Metro. Notably missing from the new interface is a Start button and Start Menu. Many users do not like it, much preferring the interface of earlier versions — Windows 7, Windows X…
Many of my clients call in with monstrous Gmail overloading issues with Outlook. A quick tip is to turn off the All Mail and Important folders from synching. Here is a quick video I made to show you how to turn off these and other folders in Gmail s…

618 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question