Jump to content

Recommended Posts

Posted

Hi Guys ,

 

Since coming back from holiday i have noticed something sending out mail via our exchange 2003 smtp server .

 

Its managed to send out like 15k emails out on a random day !

 

Its confusing me where its coming from , i dont think its an internal machine as its been sending out on the weekend and we only have 1 machine on all the time ( apart from the servers) .

 

its not using an internal account but using it own outside address ( its pretending to be banks etc )

 

Outside relay is disabled so its not that .

 

Can some one relay if they manage to obtain admin password etc ?

 

Many thanks

Luke

Posted

Thanks .

 

Had a look at that already , We have GFI mail essentials which blocks spam but unsure how this is happening tbh ! as i have checked all servers and any desktops that have been on and they all seem ok !.

 

Im thinking maybe some one is authenticating with a username and password somehow to send the spam

Posted

intresting ...

 

'Is the anonomous access (as mentioned in the website link) switched off?'

 

if i untick this , wont it stop all incoming mail beacause they cant connect to the SMTP to send mail ?

Posted (edited)
What's a "Relay"?

 

First let's see what "relaying" is:

1.

A user in your domain wants to send e-mail to another user in your domain - This is NOT relaying.

 

2.

An outside user (from the Internet) wants to send e-mail to another user in your domain - This is NOT relaying.

 

3.

A user in your domain wants to send e-mail to an outside user (on the Internet) - This IS relaying.

 

4.

An outside user (from the Internet) wants to send e-mail to an outside user (on the Internet) - This IS relaying.

 

 

It shouldnt stop all incoming mail (see point 2 above), Personally i would disable it (as per the website link above) and try sending an email from my gmail account and see if it gets through :)

 

If you read the article, you can also put relay restrictions if needed.

 

nick

Edited by bart21
cant spell!! :)
Posted (edited)

Im pretty sure if i enable that its going its going to disable all incoming mail . As its not todo with the relay but more to do with the SMTP server and allowing users to send incoming mail without authenticating if i read that correctly.

 

I enabled logging the other day on messages and can see that a lot of the mail is coming from a outside source IP.

 

i have just enabled also SMTP logging , so should hopefully when they send out there next lot of messages see what user is authenticating . Also enabled account logon audit IN GP to see auth requests.

 

Under relays allow all PC authentication was enabled , I unchecked this and added all internal ranges only

Edited by 2097
Posted

1. By default exch 2003 wont allow relaying unless a config has been changed,

2. GFI will prevent spam but that doesnt mean it will prevent relaying, only spam coming into your Org.

3. It could be spyware/virus internally on your network.

4. Have yoyu got AV deployed on all your desktop and servers and are they up to date?

5. Can you verify point 4? Do you have centralised reporting for your Av to show update status?

6. When messgae are sent, are t hey sent internally to users or externally?

7. Can you post a message header of one?

8. Check Exch 2003 MT and SMTP logs (if not turned on turn on now).

9. KB posted by Bart is good, follow that.

10. If your concerned then describe your mail setup? Exch? gateways? Firewalls, how meesage flow internally and externally.

 

Thanks

Sukh

Posted

Thanks for the post

 

After enabling SMTP logs ive noticed this is a external client

 

They are relaying , and are using it to spam outside accounts

 

Ive enabled some more logging to see what account they are using to authenticate.

 

It is currently enabled that all Authenticated users can Relay and Submit , I have modified what computers can use relay .. I think i might just enable it so only Admins can use the relay service , So this will still allow my applications to send out some emails

Posted

found out the authenticating user .. test1 was the account name .. I think i could guess the password lol !

 

disabled the account for now . Think it was setup prior to my arrival

 

Thanks every one for the help

 

Manage to catch it out with using MXexchange transport logging . no other logs will log it :(

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...