Solved

Blacklisted : CBL - Exchange 2010 - Need Assitance

Posted on 2013-12-26
4
475 Views
Last Modified: 2013-12-26
Have Exchange 2010 has been running fine, no issues.
Got call from client, cannot send.
Checked MX Toolbox
Listed on SORBS, Spamhaus Zen, CBL
CBL says trojan or botnet is on network

Checked server, Queues are not filling up with outbound mail, thus I don't think I have a compromised user account and not relaying, that I can tell.

I am in charge of the server side of the house, what are the steps I should take to verify the server is not compromised.

Please advise
0
Comment
Question by:tech911
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 25

Expert Comment

by:Tony Giangreco
ID: 39740176
Run a full anti virus & anti spyware scan on all systems.  I'd run a few different apps to verify everything is clean.

Start with http://windows.microsoft.com/en-us/windows/security-essentials-download on all Pc's

Follow up with Malwarebytes and check all boxes for popups and browser hijacks.

Some spyware and virus apps have their own SMTP engines that bypass Exchange to send mail.
0
 
LVL 3

Author Comment

by:tech911
ID: 39740223
Ran Sec Essentials and MWbytes on Server, Clean.
Desktop Team is checking User Desktops
Anything else I should be doing or looking at on the server?
0
 
LVL 25

Assisted Solution

by:Tony Giangreco
Tony Giangreco earned 250 total points
ID: 39740255
If you have a firewall, see if it tells you what box is sending out Smtp traffic. You can also setup anti spam service for incoming and outgoing mail. We have used this service on all our clients and it works very well.

This service quarentines incoming and outgoing spam which should stop you from being black listed again. It should also trap the outgoing spam you have right now.

Take a look at GFI max Mail Essentials
www.gfi.com
0
 
LVL 76

Accepted Solution

by:
Alan Hardisty earned 250 total points
ID: 39740450
Make sure you block TCP Port 25 outbound for all IP addresses other than the Exchange server if you haven't already.

If you have already, then you have a problem on the server, if not, then it's more likely a network computer.

Alan
0

Featured Post

Automating Your MSP Business

The road to profitability.
Delivering superior services is key to ensuring customer satisfaction and the consequent long-term relationships that enable MSPs to lock in predictable, recurring revenue. What's the best way to deliver superior service? One word: automation.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

How to resolve IMCEAEX NDRs in Exchange or Exchange Online related to invalid X500 addresses.
This article will help to fix the below error for MS Exchange server 2010 I. Out Of office not working II. Certificate error "name on the security certificate is invalid or does not match the name of the site" III. Make Internal URLs and External…
In this Micro Video tutorial you will learn the basics about Database Availability Groups and How to configure one using a live Exchange Server Environment. The video tutorial explains the basics of the Exchange server Database Availability grou…
how to add IIS SMTP to handle application/Scanner relays into office 365.

627 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question