Re: NDR's



Hi Adam,

Thank you for the post. And thank our MVP Les for the answer.

>From the description, it seems that you may under the RNDR attack or the
sender just flood the spam to random recipients.

For your information:

Spammers have a new means to avoid filters built into many systems. They
take advantage of a mail systems sending of a non-delivery report (NDR)
when a message cannot be delivered as addressed and returns the original
contents. Since this follows the RFC standard, most all mail servers will
function this way. This is what is called a "Reverse NDR attack" (RNDR).
This form of attack is becoming increasingly widespread. Some users get it
so badly that over 33% of their Internet messages are attributed to this
type of spam. The end result is the spammer has attained a new form of mail
relaying. Your server's resources are being stolen to deliver spam.

How does a "Reverse NDR" attack work?
Step 1 Spam email is created with the intended spam victim's address in the
sender field and a random, fictitious recipient, at your domain, in the To:
field.
Step 2 Your mail server cannot deliver the message and sends an NDR email
back to what appears to be the sender of the original message, the spam
victim.
Step 3 The return email carries the non-delivery report and possibly the
original spam message. Thinking it is email they sent, the spam victim
reads the NDR and the included spam.

What are the symptoms of a RNDR attack?
1. Sluggish email delivery
2. Outbound queues full of non-delivery notices
3. Excessive admin time to clear outbound queues
If you are experiencing any of the above, chances are good your mail server
is under attack.

Just as Les said, those NDR spam can be resolved with two simple checkboxes
on Recipient Filtering of the Message Delivery section of Global Settings.

For your information:

Exchange queues fill with many non-delivery reports from the postmaster
account in Small Business Server 2003
http://support.microsoft.com/default.aspx?scid=kb;en-us;886208

If it is not your case or it dose not work, please help me collect the
following information:

1. Are you using POP3 mailbox to receive mail?

2. What are the senders' addresses for those emails? Are they same?

If you have any questions please do not hesitate to let me know. I am glad
to be of assistance.

Best regards,

Jerry Zhao (MSFT)

Microsoft CSS Online Newsgroup Support

Get Secure! - www.microsoft.com/security

=====================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
=====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.



.



Relevant Pages

  • Re: Undeliveable Mail showing up from my domain postmaster (exchan
    ... > sender just flood the spam to random recipients. ... This is what is called a "Reverse NDR attack". ... > If you are experiencing any of the above, chances are good your mail server ...
    (microsoft.public.windows.server.sbs)
  • Re: Undeliveable Mail showing up from my domain postmaster (exchange 2
    ... sender just flood the spam to random recipients. ... This is what is called a "Reverse NDR attack". ...
    (microsoft.public.windows.server.sbs)
  • Re: Malware infection signs
    ... Common problem with Exchange, easy fix, no need to disconnect. ... external spam attack using their NDR mechanism to bounce spam to the ... down NDR it only go to the Exchange sorter and stops there. ...
    (microsoft.public.windows.server.sbs)
  • Re: IIS 5s SMTP and Stopping NDRs ?
    ... If I can get the mail server to just ... kindly sending NDR reports for every email it receives that is not ... to an existing mailbox. ... the absence of any spam detection at that level. ...
    (microsoft.public.inetserver.iis.smtp_nntp)
  • Re: massive fake returned e-mail
    ... the only reason why all these NDRs are getting sent back is because the receiving mail servers are accepting the spam and then checking if the e-mail is deliverable afterwhich they send out *new* e-mails as the NDRs. ... If the receiving mail server rejected the spam DURING the mail session then it would reject non-deliverable mail at that time. ... Instead of accepting the spam and then later sending back an NDR, rejecting the attempted delivery during the mail session means the actual sending mail server gets notified of the non-delivery. ...
    (microsoft.public.outlook)