Error » Microsoft Error! » Microsoft Operating Systems Error » Microsoft windows vista error » Exchange 2003 SMTP Queue filling with thousands of spam emails even when not on netwo

Microsoft windows vista error all errors related to microsoft windows vista

Post New Thread Reply
  Exchange 2003 SMTP Queue filling with thousands of spam emails even when not on netwo
LinkBack Thread Tools Display Modes
Old 28-Mar-2007, 12:45 AM   #1 (permalink)
Fixed Error!
 
Iphone's Avatar

Posts: 4,202
Join Date: Mar 2007
Rep Power: 6 Iphone is on a distinguished road

IM:
Default Exchange 2003 SMTP Queue filling with thousands of spam emails even when not on netwo

I have got one of my customers' servers here as it has gone crazy. It is running SBS 2003. It is generating an enormous amount of SPAM messages and from reading through many questions here is sounds exactly like a dictionary attack. All except for the fact that I have configured (and quadruple checked the set up of) recipient filtering.

I run Symantec Antivirus on it, I have just installed a trial version of Symantec Antivirus for Microsoft Exchange and another malware scanning app that I can't remember the name of right now. They have all come up with nothing on full scans.

I am having to constantly use the aqadmcli delmsg flags=all tool to empty the smtp queues, but I think the mail is generating at least as fast as the tool deletes it.

About half of the messages when I check them in the queue are from postmaster@domainname.co.uk which points towards an NDR attack, but I am sure that I have switched off NDRs.

The messages are mainly going to msa.hinet.net, yahoo.com.tw, etc.

So to recap, no relaying, tarpit setup (regisrty entry checked), recipient filtering set up, up to date antivirus but smtp queue filling rapidly with spam even when unplugged from the network.

Please help, I am going out of my mind here and have been working till 4am for the last couple of days trying to sort this out!!!
Iphone is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit!
Reply With Quote
   


   
Old 28-Mar-2007, 12:45 AM   #2 (permalink)
Fixed Error!
 
Iphone's Avatar

Posts: 4,202
Join Date: Mar 2007
Rep Power: 6 Iphone is on a distinguished road

IM:
Default Re: Exchange 2003 SMTP Queue filling with thousands of spam emails even when not on n

The messages could appear to be still being generated, but I doubt whether they are.
ESM is notorious for not showing the true extent of the queues. A spammer will usually drop and run, and they will drop many thousands of messages in a single hit. Exchange ESM cannot show you all of those messages in one go, so it looks like they continue to appear even with the machine disconnected.

Spam doesn't generate on its own. The spammer is usually created elsewhere and is simply sent through the compromised machine. To get something on to the machine, the server would have to be totally compromised - and the level of compromise depends on how the server was exposed to the internet.

As for the eml messages that you may see with old dates, if the server has been abused before what can often happen is that something else gets hold of the messages and stops Exchange from flushing them out. AV is the common culprit. I have also seen Exchange do odd things when it is under a very heavy load and you may have seen some signs of that.

As I wrote in my article, you usually have to repeat the process for cleaning the queues a number of times; my record is 15 over a six hour period. Only once you can leave the server for a couple of hours disconnected from the internet with clean queues do you know that the server is clean.

I doubt if the source of the messages is a machine on your network. A spammer isn't interested in finding a server to bounce the messages through. If a machine on your network has been compromised your Exchange server wouldn't know about it, as the messages would be going straight out.
Think about it for a moment - the spammer has to a, compromise the machine, b, find the Exchange server, c, create the messages in MAPI not SMTP to get Exchange to process the messages. Alternatively, the spammer just installs an SMTP engine on the machine and sends the spam out. I think I know which one is most likely.

Have you worked out how the email messages got on to your server? If they are postmaster@ messages then it is NDR spam, if not, then it was most likely either an open relay or an authenticated relay. If it was authenticated relay you need to change your administrator password. Don't bother with any other accounts, as the administrator account is the only target for this type of attack (unless a user has been very stupid with their username and password). However you may want to force all users to change their passwords or call in for a new password as a lesson for anyone who might be tempted to hand out their password to anyone else.
Iphone is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit!
Reply With Quote
Old 13-Apr-2007, 09:19 AM   #3 (permalink)
Fix my Error!
 
wmofskye's Avatar

Posts: 1
Join Date: Apr 2007
Rep Power: 0 wmofskye is on a distinguished road

IM:
Default Re: Exchange 2003 SMTP Queue filling with thousands of spam emails even when not on n

I'm having the same issue. Fighting to resolve ASAP. Can you point me in the right direction to resolve this issue?
wmofskye is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit!
Reply With Quote
Post New Thread Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT -8. The time now is 05:27 PM.

Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0

DMCA Policy

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227