Re: Help SBS2003 acting as relay



"dmh" <fake@xxxxxxxxxxxxxxxxxxxxxx> wrote in message news:eu5vu4h39658p0l0eimggnbkri751vg8ag@xxxxxxxxxx
Hi,
Could use some help at pinpointing where the hole is in my clients
setup.
First symptom was problem in sending emails.

1. Fully patched SBS2003 Standard. Exchange patched to SP2.

2. Confirmed multiple times that the SMTP Connector and Default SMTP
Virtual Server is setup correctly as per KB324958. No changes
apparent.

3. MXToolbox stills shows the server as an Open Relay.

4. Queue has over 160,000 emails waiting (currently directed to
99.99.99.99). Viewing messages shows them to be mostly asian language.
These build very rapidly after being cleared out.

This system has worked without issues for about 10 months. The email
relay problem started about 2-3 days ago.

I'm currently thinking that a client machine maybe at fault. Nothing
obvious has shown up after setting SMTP Protocol logging to maximum.

Just unchecked "Allow all computers which successfully authenticate to
relay, regardless of the list above" to see if that makes a
difference.

Any tips or checks you can suggest are most appreciated.

Particularly usefull would be a quick method of cleaning out the
queue. The method of selecting messages and choosing Delete All
Messages (No NDR) is rather painfull.

Thank you.

David


My first feeling is a user account's credential got hijacked. I worked in a 5000+ large environment where one account got hijacked while he was at home using OWA (webmail). His account was used to authenticate relays. We didn't catch it until 20,000+ relayed messages went through effectively putting the company's IP on the SORBS list (www.sorbs.net). That was a pain to get off the list because they want $50 to get your IP off the list. (Personal note: What a scam!)

If you have SMTP logging enabled, see if you can find out what account, if any, is being used to authenticate the relay. If they were using a direct relay through the SMTP service, I wouldn't imagine Message Tracking (if you have it enabled) will show the message, unless they used the user's account (assuming if it were hijacked) that sent it.

As for cleaning out the queues, stop the SMTP service, then go into the VS folder under the Exchange folder and rename the queue folder to queue.old, then restart the SMTP service. It will create a new empty queue.

--
Ace

This posting is provided "AS-IS" with no warranties or guarantees and
confers no rights.

Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSA Messaging, MCT
Microsoft Certified Trainer
aceman@xxxxxxxxxxxxxxxxxxxxxxx

For urgent issues, you may want to contact Microsoft PSS directly. Please
check http://support.microsoft.com for regional support phone numbers.

.



Relevant Pages

  • Re: SMTP Queue - Suspect virus/spam
    ... There was no mail in the smtp queue. ... and 30 minutes later went to go and check the queues and hey hey 9000 emails. ... If your server has been sending out ...
    (microsoft.public.windows.server.sbs)
  • Re: Joe Jobbing?
    ... be /nothing/ in the allow relay box. ... successfully authenticate" should /not/ be checked on your server. ... in the "Configure the Exchange Server to Block Open SMTP Relaying" ... > There are internal queues within Exchange that aren't visible to the queue ...
    (microsoft.public.exchange2000.admin)
  • Re: Yet another request to force MSs brain dead SMTP service to process its queue
    ... The problem is that the SMTP server can not know if a domain is ... I want it to plow through the queue and badmail ... Can't find out until it processes the 4000 emails that are ...
    (microsoft.public.inetserver.iis.smtp_nntp)
  • Re: Remote Web Workplace setup - now I cant receive emails!
    ... But I've unchecked that relay box as you've suggested. ... But now I cannot receive emails through Exchange. ... Our domain is hosted by Demon Internet and they have repointed the MX ... SMTP error from remote mailer after RCPT ...
    (microsoft.public.windows.server.sbs)
  • Re: HELP - cant figure out this violation!
    ... > (SMTP mail). ... > the queue quickly fills up and grows from just a couple of delivery ... This wouldn't be a relay issue, but make sure you have authenticated relay ...
    (microsoft.public.exchange.admin)