Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

Exchange mail Account hacked ?

Posted on 2015-02-03
4
Medium Priority
?
72 Views
Last Modified: 2016-06-23
My Company is using Exchange 2010 as it mail servers.  It appears the mail server is now hacked as  hackers are using  one the company's  valid email account on the exchange to send malicious mail/ messages to  our client.
How do I stop this ?
0
Comment
Question by:zugulu
3 Comments
 
LVL 76

Accepted Solution

by:
Alan Hardisty earned 672 total points
ID: 40585979
Change the password for the account immediately and then restart the Transport Service.

Then empty out any queues of invalid messages and review the security of your server settings / password settings as they sound like you have weak passwords and they aren't changed often enough.

Alan
0
 
LVL 4

Assisted Solution

by:Praveen Kumar Bonala
Praveen Kumar Bonala earned 664 total points
ID: 40586045
Most probably there could be a misconfiguration in SMTP relay.
In a Small Business Server environment, you may have to prevent your Microsoft Exchange Server-based server from being used as an open relay SMTP server for unsolicited commercial e-mail messages, or spam. You may also have to clean up the Exchange server's SMTP queues to delete the unsolicited commercial e-mail messages. If your Exchange server is being used as an open SMTP relay.

Please check following link to configure SMTP Relay.
http://support.microsoft.com/kb/324958
0
 
LVL 19

Assisted Solution

by:Miguel Angel Perez Muñoz
Miguel Angel Perez Muñoz earned 664 total points
ID: 40586056
I suggest you force all users change his passwords and set a expiry policy.

To force all users (domain administrator too) you can run this from powershell:
import-module activedirectory
get-aduser -filter {objectclass -eq "user"} | set-aduser -ChangePasswordAtNextLogon $true
0

Featured Post

Simplify Active Directory Administration

Administration of Active Directory does not have to be hard.  Too often what should be a simple task is made more difficult than it needs to be.The solution?  Hyena from SystemTools Software.  With ease-of-use as well as powerful importing and bulk updating capabilities.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Mailbox Corruption is a nightmare every Exchange DBA wishes he never has. Recovering from it can be super-hectic if not entirely futile. And though techniques like the New-MailboxRepairRequest cmdlet have been designed to help with fixing minor corr…
Last month Marc Laliberte, WatchGuard’s Senior Threat Analyst, contributed reviewed the three major email authentication anti-phishing technology standards: SPF, DKIM, and DMARC. Learn more in part 2 of the series originally posted in Cyber Defense …
how to add IIS SMTP to handle application/Scanner relays into office 365.
This video discusses moving either the default database or any database to a new volume.
Suggested Courses
Course of the Month14 days, 9 hours left to enroll

577 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question