Re: Inside user spamming

From: exchangerookie1994 (exchangerookie1994_at_discussions.microsoft.com)
Date: 12/06/04

  • Next message: exchangerookie1994: "RE: No ESMTP response - ehlo test.com 500 5.3.3 Unrecognized command"
    Date: Mon, 6 Dec 2004 03:41:03 -0800
    
    

    Thanks for the response
    I have read that. I have SMTP logging set to maximum hoping to catch the
    cracked user account. I have also been running Mail monitor on the exchange
    server. Monitoring all traffice going in and out of smtp. No one has
    authenticated to smtp. I have relaying allowed to internal ip range to allow
    mail flow. This client has almost all pop3 clients on inside. Is there a tool
    for exchange that will log the amount of mail coming from a specific inside
    pc?

    Thanks

    "Leif Pedersen [MVP]" wrote:

    > Hi,
    >
    > This article explains how to find the culprit:
    > http://www.vamsoft.com/orf/authattack.asp
    >
    > Leif
    >
    >
    >
    > "exchangerookie1994" <exchangerookie1994@discussions.microsoft.com> skrev i
    > en meddelelse news:2A7EC9F3-1591-43E8-BD14-17ADBAE33E62@microsoft.com...
    > > I have a set up Exch2000 fresh load. I have locked relay capabilties to
    > local
    > > ip subnet. I have tested for open relay from outside - good. I have
    > unchecked
    > > allow authenticated users to relay setting. My smtp queue is filling fast.
    > Is
    > > there a utilty /software to see were this mail is coming from. I think it
    > has
    > > to be someone on inside (domain user). I have also turned on logging on
    > > MStransport - smtp protocol to maximim
    > > logging.
    > > Please help
    >
    >
    >


  • Next message: exchangerookie1994: "RE: No ESMTP response - ehlo test.com 500 5.3.3 Unrecognized command"

    Relevant Pages

    • Re: Exchange 2000 message Tracking Question
      ... Outlook rules, views, other POP3 clients that may have downloaded/deleted ... If the message tracking logs indicate the message was ... > had sent an email on Jan 12 to another internal user. ... > 1/12/2005 12:43PM SMTP: Started Message Submission to Advance Queue ...
      (microsoft.public.exchange.admin)
    • pop3, disk quotas and lock users
      ... which is configured with pop before smtp, this is a inherited system. ... when they use their pop3 clients, a copy of the mail is made in the same ... Adding more quota won't solve it, cause the more mail they get, more ... I can't change the pop before smtp to smtp-auth. ...
      (SunManagers)
    • Re: SMTP AUTH attack possible on E2K7?
      ... allows external IMAP and POP3 clients, ... And when those external users with POP3 clients want to hit ... means *that* server is vulnerable to SMTP AUTH attacks. ...
      (microsoft.public.exchange.admin)
    • Re: SSL with SMTP only for Outlook clients
      ... Your best bet here would be to set up an additional SMTP Virtual Server ... specifically for your POP3 clients. ... you'll have to configure it to listen on a different port ...
      (microsoft.public.exchange.admin)

    Loading