Re: Exchange 2000 Being used as Relay

From: Enno Lenze (nntp_06_at_verbrennung.org)
Date: 09/09/04


Date: Thu, 09 Sep 2004 09:42:13 +0200


> First, where is the e-mail postmaster@mydomain.com address
> come from? It's not anywhere on my server.

Well, everyone on the net can send with every adress, thats theproblem.
View the header.

> Second, I have the Default SMTP Virtual Server set to
> default, which MS calims, Open relay is closed.

Test ist:

start -> run command

telnet SERVER 25<enter>
on the promt write:
helo<enter>
mail from:geroge@whitehouse.gov<enter>
rcpt to:nntp_06@verbrennung.org<enter>
Subject: foobar!<enter>
just a test<enter>
.<enter>
quit<enter>

if i ge a mail from george we kno that you have an open relay :)

> Users receive many SPAM mails. one of the user receive
> SPAMs that are sent to (on the TO filed) an e-mail address
> that is not in our network and yet it's going into his
> mailbox, example, billy@mydomain.com. I don't see that
> the message was BCC either. How is this occuring?

_B_CC fields are not visible usually. Its the _blind_ carbon copy :)
the mail is maybe FROM me@here.com TO you@there.com BCC user@yourdomain.com

On thing against spam (which works here for about 95% of spam) is gray
listing.

The first time a mail is delivered you response an error 450 (pleaase
try again). 95% of the spammers wont try again. Every normal configured
mailserver will try again.

But i dont know how to do taht with exchange. Im still looking for good
spam prevention in exchange 2k as well.

hth, enno

-- 
http://www.verbrennung.org
This message was send early in the morning.
Please don't blame me, if it makes no sense.


Relevant Pages

  • Re: Administrator account hijacked?
    ... Best 2 minutes spent on an Exchange ... Non-delivery reports have a very legitimate purpose and are used to ... global white lists defined by mail server administrators. ... software does not attempt to filter non-delivery reports for spam ...
    (microsoft.public.windows.server.sbs)
  • Re: SMTP Scans
    ... Opinion seems to be divided 99/1 that the scans are bad. ... an open relay, not only that, they are also scanning our mx listed secondary ... >server is pumping it flat out for a day or a week or a month. ... >Or to put it this way: why do you think earthlink, aol and a LOT of spam ...
    (Incidents)
  • Re: Non-Existing addresses
    ... Are you running any kind of spam filter gateway in front of your Exchange ... or is your Exchange server having to deal with it all? ...
    (microsoft.public.exchange.admin)
  • Re: SPAM Blocking Measures
    ... No need to configure a gateway. ... Exchange Server? ... I prefer Spam Soap at www.spamsoap.com, ... Exchange AV software) and Fail Safe Spooling in case your server is down ...
    (microsoft.public.exchange.admin)
  • Re: How does Symantec Multi-Tier v10.0 stack up?
    ... won't kill the server like some Symantec AV stuff does). ... >> Thanks for the reply - does the Mail Security for Exchange not come as part ... >> Seems like you are doing a good job of the Spam - I want to be able to this ...
    (microsoft.public.windows.server.sbs)