I want to make one comment on this that I found last week. I might be missing something small, but what I found was that Exchange 2000 allows relaying by means of using <"encapsulated SMTP addresses">. I know that this was fixed post-sp3 for Exchange 5.5, but can anyone else test this and see if it is a vulnerability in Exchange 2000. The settings I have are defaults. Regular relaying is not allowed, but sneaky relaying works. Any thoughts?
Ben Winzenz, MCSE Network/Systems Administrator Peregrine Systems, Inc. -----Original Message----- From: Lefkovics, William [mailto:[EMAIL PROTECTED]] Sent: Monday, November 19, 2001 12:03 PM To: MS-Exchange Admin Issues Subject: RE: IMPORTANT Realy Problem 300 Mails per minute Exchange2000, look at the SMTP Virtual Server Properties in Exchange System Manager. Look under the Access tab. You control who uses your server. Also, Exchange2000 is secure by default, so somebody has already visited this tab. William -----Original Message----- From: BOERO MANSILLA Roberto [mailto:[EMAIL PROTECTED]] Sent: Monday, November 19, 2001 9:02 AM To: MS-Exchange Admin Issues Subject: RE: IMPORTANT Realy Problem 300 Mails per minute Importance: High exchange 2000 each mail is 23 k -----Mensaje original----- De: Lefkovics, William [mailto:[EMAIL PROTECTED]] Enviado el: Lunes, 19 de Noviembre de 2001 01:36 p.m. Para: MS-Exchange Admin Issues Asunto: RE: IMPORTANT Realy Problem 300 Mails per minute Good thing you sent that with the High Importance flag... 300 mails per minute? 60x300= 18,000/hour! Larry Ellison won't believe you! Here is the de facto standard for securing Exchange5.5 from relay: http://www.exchangeadmin.com/Articles/Index.cfm?ArticleID=7696 I forget... did you have Exchange2000? Or Sendmail? William -----Original Message----- From: BOERO MANSILLA Roberto [mailto:[EMAIL PROTECTED]] Sent: Monday, November 19, 2001 4:23 AM To: MS-Exchange Admin Issues Subject: IMPORTANT Realy Problem 300 Mails per minute Importance: High Hi all. I am having a little problem, my servers are been used to relay spamming mail, can anyone tell how to fix that, or a link where i can get an idea what to do? thanks best regards List Charter and FAQ at: http://www.sunbelt-software.com/exchange_list_charter.htm List Charter and FAQ at: http://www.sunbelt-software.com/exchange_list_charter.htm List Charter and FAQ at: http://www.sunbelt-software.com/exchange_list_charter.htm List Charter and FAQ at: http://www.sunbelt-software.com/exchange_list_charter.htm