Inbound email attacks going to whole of GAL

From: Mark Apolony (anonymous_at_discussions.microsoft.com)
Date: 05/05/04


Date: Tue, 4 May 2004 21:51:03 -0700

I am running Exchange 2003 on WServer 2003. We are receiving email attacks where a message is delivered to every member of the GAL, yet the from & to address are not valid. ie. the from address has shown both internal and external looking addresses, and the to address will be something like you@domain.com.au or something similar which is not valid on our system.

I know we are all fighting spam, spoofing, viruses and worms, but has anyone seen this sort of behaviour before? I am concerned that something is coming in the backdoor and I want to be able to stop it.



Relevant Pages