Re: NDR Spam



In news:1158929055.657888.67710@xxxxxxxxxxxxxxxxxxxxxxxxxxx,
chrisskrod@xxxxxxxxx <chrisskrod@xxxxxxxxx> typed:
I have a SBS 2003 box hosting email with Exchange. Many of the users
are getting NDR reports with spam in them every few minutes. I have
Symantec Mail Agent for Exchange updated and running. Clients report
no virus problems.
I have a telneted to the mail server from the outside. The reply to
telnet xxx.xxx.xxx.xxx 25 is a different name than my mail server.

That's not uncommon.

I
type in the correct IP address and receive the wrong hostname.

What are you expecting to see, and what are you seeing, and from where?

When I
test for open relay, it responds with the 250 ok instead of blocking.

How are you testing? Unless you or someone deliberately enabled relay, all
that's enabled is authenticated relay. However, check - and also disable
auth relay unless you need it. And if you *do* need it, you really want to
have a good complex password policy to prevent it being exploited.


I went through the Microsoft KB for closing an open relay. Default
SMTP and SmallBusiness SMTP set as they should be.
Is there a way to determine if the emails are originating elsewhere,
if the sender address was being spoofed.

Check the headers....

The mails that are going out

Going out, or coming in?

are coming from mydomain@mydomain which is not one of my email
addresses. Thanks,

That's a pretty good sign you're being spoofed.

Do you have SP2 installed, and filtering enabled? You should....


Chris



.



Relevant Pages

  • NDR Spam
    ... are getting NDR reports with spam in them every few minutes. ... Symantec Mail Agent for Exchange updated and running. ... I have a telneted to the mail server from the outside. ... and SmallBusiness SMTP set as they should be. ...
    (microsoft.public.windows.server.sbs)
  • Re: Ouch! My SBS got hacked! Please help me not be a spammer
    ... With any mail server, the first thing to check is not a Windows virus. ... You should be checking your SMTP _relay_ settings. ... I have eTrust Anti Virus Version: 7.0.139 running with the latest signatures on SBS and all the other client computers. ...
    (microsoft.public.windows.server.sbs)
  • Re: DNS / ISA and Exchange issue
    ... This is neither ISA nor DNS. ... The key to this is the error message: ... The mail server is not configured to accept mail for smtp.ourdomain.com. ... to relay for mir@smtp.ourdomain.com (in reply to RCPT TO ...
    (microsoft.public.isa.configuration)
  • Re: Growing SMTP queue to random domains
    ... Spam Marshall. ... > The only knowledge base article I could find describes this problem ... > only if the mail server is open for relay or is on a black list of some ... The servers that are experiencing this issue are not open for relay ...
    (microsoft.public.exchange.admin)
  • Re: MX & A Records for Dual Domain Smtp Host
    ... Relay is for outgoing mail and doesn't require an MX record. ... outgoing email to another mail server. ... Here is a good article I found that discusses where to look in your config ...
    (microsoft.public.windows.server.dns)