I want to make one comment on this that I found last week.  I might be
missing something small, but what I found was that Exchange 2000 allows
relaying by means of using <"encapsulated SMTP addresses">.  I know that
this was fixed post-sp3 for Exchange 5.5, but can anyone else test this and
see if it is a vulnerability in Exchange 2000.  The settings I have are
defaults.  Regular relaying is not allowed, but sneaky relaying works.  Any
thoughts?

Ben Winzenz, MCSE
Network/Systems Administrator
Peregrine Systems, Inc.

 -----Original Message-----
From:   Lefkovics, William [mailto:[EMAIL PROTECTED]] 
Sent:   Monday, November 19, 2001 12:03 PM
To:     MS-Exchange Admin Issues
Subject:        RE: IMPORTANT Realy Problem  300 Mails per minute

Exchange2000, look at the SMTP Virtual Server Properties in Exchange System
Manager.  Look under the Access tab.  You control who uses your server.

Also, Exchange2000 is secure by default, so somebody has already visited
this tab.

William 

-----Original Message-----
From: BOERO MANSILLA Roberto [mailto:[EMAIL PROTECTED]]
Sent: Monday, November 19, 2001 9:02 AM
To: MS-Exchange Admin Issues
Subject: RE: IMPORTANT Realy Problem 300 Mails per minute
Importance: High


exchange 2000
each mail is 23 k

-----Mensaje original-----
De: Lefkovics, William [mailto:[EMAIL PROTECTED]]
Enviado el: Lunes, 19 de Noviembre de 2001 01:36 p.m.
Para: MS-Exchange Admin Issues
Asunto: RE: IMPORTANT Realy Problem 300 Mails per minute


Good thing you sent that with the High Importance flag...
300 mails per minute?  60x300= 18,000/hour!   Larry Ellison won't
believe
you!

Here is the de facto standard for securing Exchange5.5 from relay:
http://www.exchangeadmin.com/Articles/Index.cfm?ArticleID=7696

I forget... did you have Exchange2000?  Or Sendmail?


William

-----Original Message-----
From: BOERO MANSILLA Roberto [mailto:[EMAIL PROTECTED]]
Sent: Monday, November 19, 2001 4:23 AM
To: MS-Exchange Admin Issues
Subject: IMPORTANT Realy Problem 300 Mails per minute
Importance: High


Hi all.
I am having a little problem, my servers are been used to relay spamming
mail, can anyone tell how to fix that, or a link where i can get an idea
what to do?


thanks 
best regards

List Charter and FAQ at:
http://www.sunbelt-software.com/exchange_list_charter.htm


List Charter and FAQ at:
http://www.sunbelt-software.com/exchange_list_charter.htm

List Charter and FAQ at:
http://www.sunbelt-software.com/exchange_list_charter.htm

List Charter and FAQ at:
http://www.sunbelt-software.com/exchange_list_charter.htm

Reply via email to