Re: Someone has meddled with Active Directory users (has set email forwarding to external account)- how can I tell who? - Urgent!

From: Lanwench [MVP - Exchange] (lanwench_at_heybuddy.donotsendme.unsolicitedmail.atyahoo.com)
Date: 01/02/05

  • Next message: Lanwench [MVP - Exchange]: "Re: Outlook Web Access, ExchWeb-Trouble"
    Date: Sat, 1 Jan 2005 22:07:11 -0500
    
    

    swilliams@cromwells.co.uk wrote:
    > We recently had what appears to be someone logging onto the Exchange
    > 2000 server and setting any mail sent to two domain users to be also
    > forwarded to an external recipient (Contact) that I had set up
    > previously. This is the second time this has happened in 6 months, and
    > meant the user whose Contact address this was, was getting mail
    > destined for these 2 users- obviously a big security risk. Is there
    > ANY way of finding out which domain user might have made the changes
    > to the Active Directory objects for these users? Neither previously
    > had any forwarding set up in Delivery Options.
    >
    >
    > There doesn't seem to be anything in Event Viewer for this kind of
    > change, and I can't see any way at all how Active Directory would
    > choose to set up forwarding to an external recipient in this way.
    > Furthermore this is the second time this has occurred and there appear
    > to be patterns (personnel-wise) linking the two events. I'm almost
    > completely certain that this is deliberate. I have been tasked with
    > finding out who has done this as quickly as possible.
    >
    >
    > This is extremely urgent, so any help anyone can give me would be much
    > appreciated! Please reply to the thread or email me
    > (swilli...@cromwells.co.uk). Thanks for your assistance.

    This can't happen accidentally. Start with the basics.

    Which accounts have permissions to do anything like this?
    Who knows the administrator credentials? Change the password.
    Who has physical access to the server(s)?
    Is terminal services (admin mode) enabled on this server?
    What ports are open in your Internet-facing firewall?
    Cui bono?

    Even if you can set up security auditing to log this specific sort of
    change, it's too late now that the horses are out of the barn, as it were.


  • Next message: Lanwench [MVP - Exchange]: "Re: Outlook Web Access, ExchWeb-Trouble"

    Relevant Pages

    • Re: Least amount of privileges
      ... It depends on what the domain users group has for permissions. ... Does this third party program have a service account that runs the app for ... moving this app off of your sql server and put it on a seperate server. ...
      (microsoft.public.windows.server.active_directory)
    • Re: Access rights issue with Sharepoint - newbie question
      ... as the WSS server isn't running activedirectory. ... That I took the domain users out of the domain admins group on the WSS ... one that would be making all the site-changes to the SharePoint app as ... Administrators Group) - I believe it may be because the users are not ...
      (microsoft.public.sharepoint.windowsservices)
    • Re: Access rights issue with Sharepoint - newbie question
      ... as the WSS server isn't running activedirectory. ... That I took the domain users out of the domain admins group on the WSS ... one that would be making all the site-changes to the SharePoint app as ... Administrators Group) - I believe it may be because the users are not ...
      (microsoft.public.sharepoint.windowsservices)
    • Re: Least amount of privileges
      ... the domain users don't have permissions at the root of a partition, ... Does this third party program have a service account that runs the app for ... Also you should consider moving this app off of your sql server and put it ... users are getting to this 3rd party program through Terminal Services ...
      (microsoft.public.windows.server.active_directory)
    • Re: Migrating security & sharing permissions and local groups
      ... I created some test groups locally on PC1 and added some domain users ... folders. ... I've a file server which needs to be migrated to a different hardware. ... These groups are given security and sharing permissions on the ...
      (microsoft.public.windows.server.general)

    Loading