Exchange 2003 - Clear SMTP queues after an NDR attack / Open relay




Exchange 2003 - Clear SMTP queues after an NDR attack / Open relay

- stop SMTP service
- navigate to queue directory (by default, C:\PROGRAM
FILES\EXCHSRVR\MAILROOT\VSI 1\QUEUES)
- back up 1 directory, right click directory QUEUES
- Search directory using the MS SEARCH TOOL for files containing text
"Recipient Failed"
- Deleted all files that were found

While stopping the SMTP service and deleting ALL messages in the queue
directory would certainly clear up this issue, it would also delete
any messages that were frozen in the queue (both inbound and outbound)
that were considered GOOD messages. This method identifies only
messages that are NDR replies, which usually is the result of a
reverse-NDR attack.


.



Relevant Pages

  • Exchange 2003 - Clear SMTP queues after an NDR attack / Open relay
    ... Search directory using the MS SEARCH TOOL for files containing text ... While stopping the SMTP service and deleting ALL messages in the queue ...
    (microsoft.public.exchange2000.admin)
  • Re: Purging message queues
    ... Can I view what is in the message in the queue ... then stop your SMTP service. ... >>I have blocked outgoing SMTP messages on the ISA server. ...
    (microsoft.public.exchange.admin)
  • Re: SMTP huge queue
    ... I would stop the SMTP service, ... safe to delete the contents of the queue folder manualy? ... we have a huge queue of messages. ... > Now we try to clean this queue by deleteting these messages with no NDR ...
    (microsoft.public.exchange2000.general)
  • Re: Exchange 2003 Queue Errors
    ... stop either the smtp service or the virtual smtp service in exchange you can ... > I have been getting queues warnings and errors emailed from my Exchange ... I can see that the Internet Mail SMTP connector queue ... mailsweeper server and reason is 'the semaphore timeout period has expired'. ...
    (microsoft.public.exchange.admin)
  • Re: Unable to remove messages in the Queue
    ... I restarted the SMTP service and the email was cleared. ... the suggestion. ... > Have you guys tried restarting the SMTP virtual server? ... > clear your queue of bad messages. ...
    (microsoft.public.exchange2000.admin)

Loading