Re: Were we an open relay, NDR's or glitch? SBS 2003 Exchange



You got hit by a reverse NDR attack.

http://support.microsoft.com/default.aspx?scid=kb;en-us;886208

Be sure to do the tarpit also.

Gregg Hill


<mjseeley@xxxxxxxxx> wrote in message
news:1129478340.777750.185530@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
> Hi all,
>
> Well I've looked around but can't find the exact symptoms we had. The
> other day the net connection got very slow, caused by a load of data
> being sent from the server (2003 SBS). On inspection i found exchange
> had queues with thousands of emails in them. My initial thought was
> that I was an open relay. However, i'm not so sure.
>
> On inspection, ALL of the around 8000 emails in the queues were to one
> of two addresses. One was an AOL account and one a Demon account, both
> clients of ours. There were a load of identical emails going to the
> Demon address, then another load emails going to the AOL address.
> Finally there were a load of emails from postmaster@mydomain to one of
> them (can't remember which one now).
>
> So i'm thinking if we were an open relay we'd be sending emails all
> over the place, not just to two people we know. If we were just
> sending NDR's then surely they'd all be from postmaster. So why did we
> end up sending the other emails?
>
> I did notice when going therough clearing the queues that in the SMTP
> section in Exchange that as well as 192.168.0.1 being authorised, so
> was 127.0.0.1, and i'd read that this can make the server an open
> relay. I have disabled 127.0.0.1 just in case.
>
> Does anyone actually know what went on here?
>
> Many thanks.
> Mark
>


.



Relevant Pages

  • RE: un-wanted queues
    ... This could be because of Open relay. ... The KB articles describes how to block the open relay and clear the SMTP ... | Thread-Topic: un-wanted queues ... These emails are frozen and tend to pile up with time...I have to manually ...
    (microsoft.public.exchange2000.admin)
  • Re: exchange -
    ... i cant seem to sycn emails with my server even if i am connected to teh ... >> synchronization software. ... >> find a load of info on it and how great it is but no where that says ...
    (microsoft.public.pocketpc.activesync)
  • Re: Custom CSS in Mail
    ... Paolo Cordone wrote: ... whatever fonts the designers of HTML-rich emails have chosen. ... I have the option to load images from remote servers ...
    (comp.sys.mac.comm)
  • Outlook does not recognise his products
    ... I had to fully format the hd and firstly I saved the files *.pst. ... Once rebuilt the system I've been trying to load up old emails ...
    (microsoft.public.outlook.general)
  • Outlook2003 does not recognise his products
    ... I had to fully format the hd and firstly I saved the files *.pst. ... Once rebuilt the system I've been trying to load up old emails ...
    (microsoft.public.outlook)