Re: Relaying Breach via IIS

From: SuperGumby [SBS MVP] (not_at_your.nellie)
Date: 06/26/04


Date: Sun, 27 Jun 2004 09:49:13 +1000

remote users do not need access to SMTP to use OWA.

"Reggie Dones" <rfdones@argotech.net_nospam> wrote in message
news:%23fQrOe9WEHA.4064@TK2MSFTNGP11.phx.gbl...
> Hello all,
>
> We are running and SBS 2000 with a DMZ and noticed some ridiculous slow
> down. Figured out that the web service and smtp was being compromised.
> Although when we use netstat -an, port 25 is being used to connect to us.
> We restricted the web site security to only grant access to LAN IP's and
> that shut off the connections to several offending ip addresses,
> 69.42.100.8; 69.42.102.8 ; 80.68.244.119. However, we use the web service
> to access exchange for our remote users and will need to make it available
> to them.
>
> Can someone shed some light on this. Are there security settings that we
> can use to allow our users to access OWA without compromising our security
> and bandwidth?
>
> Thanks in advance.
> Reggie Dones
>
>



Relevant Pages