Re: Virus infected email from internal user

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Rob Bordwell (atomicdawg_at_pacbell.net)
Date: 11/02/04


Date: Mon, 1 Nov 2004 21:17:40 -0800

With SMTP, email can be made to look like it comes from any user from
any domain. An interesting thing to do is to telnet to your mail server
and try it using SMTP commands. To do this, do the following commands
from DOS prompt:

telnet <your_email_servers_ip> 25
ehlo any.server.com
mail from:<joe_blow@any.domain.com>
rcpt to:<your email addres>
data

>From here, press enter and type a message. Press <cr>.<cr> (enter-
period-enter) on a new line to end. Finally, type quit.

You've now spammed yourself. I was shocked when I first learned how
easy it was to appear to be someone else. If the email is relayed
through another server, spammers can even hide their IP.

So what can you do? As Marina suggested, get some anti virus software.
I get so many viruses sent to my Exchange server, I couldn't imagine
running without Exchange anti-virus software for a day! As far as
people spoofing your users and domain, you should implement SPF. (See
spf.pobox.com) In a nutshell, SPF uses DNS TXT records to specify which
servers can legitimately send mail for your domain. Unfortunately, most
servers do not verify an mail server using SPF. SPF is a relatively new
thing. Also, for Exchange 2000, you need third party software to verify
email server using SPF. At any rate, you should at least create a SPF
record for your domain. This will stop spammers from spoofing your
domain on servers who verify mail using SPF.

In article <336e01c4c071$865f5a90$a301280a@phx.gbl>,
anonymous@discussions.microsoft.com says...
> Occasionally we are receiving emails that appear to come
> from one email user to another. However, I have anti-
> virus on our email server and on clients. It is detected
> when the recipient receives the email, so I know the
> other internal user is not sending the infected email.
> After looking at the virus infected email, going to
> <View> <Options>. It appears that they are comingn from
> another server and it lists the IP address. It is
> received by our email server and delivered. The domains
> sending the virus are lily.com, lily.org, lily.net,
> pavilion.org, and bosslady.com.
>
> How can I disallow these emails from being delivered in
> Exchange? Is it possible?
>
> Also we've received emails from a domain name that is the
> same as ours, but with a different IP. What is up with
> that?
>
> Any repsonses would be much appreciated.
>
> Thank you,
> JamesH



Relevant Pages

  • Re: Information Store taking all available memory.
    ... There are cases where the virus software is scanning things it should not ... The aforementioned should be excluded in the virus software. ... Do Not Back Up or Scan Exchange 2000 Drive M ... Understanding Virus Scanning API 2.0 in Exchange 2000 Server ...
    (microsoft.public.exchange2000.information.store)
  • Re: Virus Problems......
    ... access the server at this point. ... >your Exchange AV scanner to get rid of this if it's ... You need to scan/clean your Exchange databases, ... >virus is, using the Exchange portion of your AV software. ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: Security issue with MS Exchange and Windows 2003 Server
    ... > user's mailboxes which is infected by a virus / trojan ... Anything you move to the new server that COULD contain a virus (like ... Why are you not running Exchange aware SMTP based AV software? ... Setup a new server, install Symantec Corporate Edition 10.0 and properly ...
    (microsoft.public.security.virus)
  • Re: Tons of errors in SB 2000
    ... Since this is a server, not workstation, just fixing windows ... what's the point of having Windows ... Now, if you have Exchange sp3 installed, you can use the ... > virus was on a workstation and not the server. ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: Calendar on Companyweb
    ... I guess I am just trying to add a layer of protection around my server by not ... change to keep the virus from my server through the anti virus on the server. ... If I use exchange, and my anit-virus fails, my server is infected. ...
    (microsoft.public.windows.server.sbs)