Jump to content

Exchange mailserver queue is in the 1000s?


Recommended Posts

Posted

Cant remember the last time I looked at the queue, but our mailserver is showing thousands of messages in the queue. Looking at the SMTP connectors, it seems we have hundreds upon hundreds of connections from all kinds of asian places and taiwanese and what not.

 

It almost looks as if we are being used as a relay for spam, though I was sure we were all nicely configured to prevent that. Anyone seen something similar?

Posted

You server is compromised to hell!!! Click 'Diable outbound mail' immediatly and dig into KB is my quick answer. You are not being used as a relay, but as a source of spam!!

Is it on a global IP?

Posted
It's a spam attack on your server. Either by brute force or dictionary based. We have a Linux box as a front end mail server to deal with such things. Exchange is dreadful at coping with them. It's also very easy to make a mistake with the configuration, causing you to be an open relay.
Posted

Yeah been fiddling with it a bit, from what I have read it appears to be a "SMTP Auth" attack, somehow one of our users details have been comprised and those details are now being used to authenticate against our server for relaying mail. We were configured to prevent unauthenticated relaying, but not for relaying via "legitimate" authentication.

 

I have implemented a few procedures I found at msexchange.org and so far it seems to be doing the trick :)

Posted

Thats my fault, I worded the original post poorly, I didnt mean actual connectors, I meant the connections list in the queue.

 

Personally I blame a lack of female cybertechbabe today :D

Posted
If your using SMTP AUTH (or any internet facing service) you need to make sure you users use hard to guess/brute force complex passwords and change them regularly.
Posted
That would be lovely, sadly our teachers can barely remember a password like "apple" , let alone something as complex as something alphanumeric. Sometimes they even forget their usernames, (first initial + surname) !!
Posted

If they all have memory sticks, you could get them to save a complex password in a text file on the memory stick and just copy n paste the password(s), if they lose it , just make sure it gets reset to something else after they report its lost or stolen or w/e.

 

http://www.grc.com/password

 

I think thats the url, creates long strong cryptographic passwords afaik.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...