Exchange 2013 DL hack

pchettri
pchettri used Ask the Experts™
on
How to find the health of distribution list and find the source if it has been hacked.

We received a an email from client suggesting they receive email from our distribution list. How to completely secure any reply form DL. should msservicepermission on reply be disabled for DL? as it is the only permission send as for DL?
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
yo_beeDirector of Information Technology

Commented:
Do you know if this address was ever used to Send As?
Look at the security on this object and see if there are any users that have rights to Send As. This would be the first place I would look. If there are no users that have this right then I would suspect that your address was spoofed.

Author

Commented:
no one has rights to send as. I was trying to find how it got hacked and could not find any logs on exchange server

Author

Commented:
it was web developer who had used DL for old campaign on centos server for auto reply. He responded after 18 hrs. Just had be worried about hacking for nothing when I did not see anything on delivery report
Director of Information Technology
Commented:
It was not truly hack most likely, but spoofed.  If you can get the recipient to send you the original e-mail you can look at the header information and see the origin of the e-mails.

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial