pchettri
asked on
Exchange 2013 DL hack
How to find the health of distribution list and find the source if it has been hacked.
We received a an email from client suggesting they receive email from our distribution list. How to completely secure any reply form DL. should msservicepermission on reply be disabled for DL? as it is the only permission send as for DL?
We received a an email from client suggesting they receive email from our distribution list. How to completely secure any reply form DL. should msservicepermission on reply be disabled for DL? as it is the only permission send as for DL?
ASKER
no one has rights to send as. I was trying to find how it got hacked and could not find any logs on exchange server
ASKER
it was web developer who had used DL for old campaign on centos server for auto reply. He responded after 18 hrs. Just had be worried about hacking for nothing when I did not see anything on delivery report
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Look at the security on this object and see if there are any users that have rights to Send As. This would be the first place I would look. If there are no users that have this right then I would suspect that your address was spoofed.