Jump to content

Recommended Posts

Posted

Hi, I have come back from the summer holidays to find that one of our exchange users passwords was compromised, and that the user was sending vast amounts of spam over the summer through Internet Mail... does anyone have any advice on securing MS exchange? the users password was bruted... the OSS mailservers I have used in the past had connection limits to hinder bruiting, but I can't see anything like that in Exchange... also is there a way of limiting a users maximum e-mails per week? sendmail had that but I can't find it in exchange?

 

thanks; I am going through the users mailbox now and a number of people have e-mailed back having a go :(

Posted
Set throttling so any user can only send so many emails in any given period. That will limit spammers should they get in. We also set limits on the number of attempts that can be made to login before logins are blocked. That limits the ability of hackers to brute force their way in.
Posted

Accounts should allways lockout after a certain amount of attempts, lesson learned. Helps if users can only access via webmail externally, something I had to do at my last place when a generic account got compromised.

 

Could of been worse, you could of been blacklisted.

Posted
I had to do at my last place when a generic account got compromised.

Another suggestion is not to allow generic logins for generic email accounts (the logins lack the accountability you need) - the enquiries@ etc. Give permissions to those who need to access them and use Outlook or OWA to give access to that mailbox.

  • 2 weeks later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...