Server hacked/being used as spammers haven...

Tech-Archive recommends: Fix windows errors by optimizing your registry



Hi there,
Our webserver recently got hit with one of those spam senders... I will say
that ORF (spam blocker) has definitely helped me in noticing that we were
being used as an
open relay... anyway, that has been fixed.

The problem is that i'm still getting some relaying through our system...
ORF does show the emails going out, but i have no clue how they are sending
the emails through our server.

We are using small business server 2000 with exchange 2k, isa2k, etc...

Basically, the spammer is able to send mail if they somehow log onto our
server (via 10.0.0.2)... if the spammer uses their own ip address, it does
get blocked. They used to be able to use fake emails to relay, but now they
use our domain mail (@uls.com) to send them out.

All emails that are sent out are from FAKE uls email accounts (they do not
exist on our system).

Any help or suggestions would be appreciated.... It has been a very very
long week :(...

My only thought is that we have a port open... we are running ISA server 2k
in front...

Thanks!

....Robin



.



Relevant Pages

  • Re: SMTP Crashing - Need Help
    ... ORF logs all the emails that come in. ... The server works as follows: Vamsoft ORF Anti-Spam Filter 2.1 binded to the ...
    (microsoft.public.exchange.connectivity)
  • RE: OMA and Outgoing Spam
    ... Someone hacked a user account and use it to spam emails; ... Your Exchange server is open relaying emails;(You have checked it ... Your server is under RNDR Attack. ... When you enable recipient filtering on the SMTP virtual server, ...
    (microsoft.public.windows.server.sbs)
  • Re: Exchange on SBS 2003 not delivering mail to user
    ... Microsoft CSS Online Newsgroup Support ... How you configured the mail server to send emails? ... on the ISP mail server when using pop3 connector to receive emails. ...
    (microsoft.public.windows.server.sbs)
  • RE: Exchange SMTP Queues full - not receiving external email
    ... I understand that you found many emails were ... attack, Reverse NDR attack or some internal workstations are infected by ... This issue can occur if your exchange server is being used as a relay ... When you enable recipient filtering (if you are using SMTP for incoming ...
    (microsoft.public.windows.server.sbs)
  • RE: SMTP sending failure, connection is dropped by remote host
    ... receive emails is correctly. ... On the SBS server, click Start, click Run, type "cmd" and click OK. ... Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)