Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations wOOdy-Soft on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

mail server compromised?

Status
Not open for further replies.

bobsa32

Technical User
Jan 19, 2006
168
Hi,

We have exchange 2003 (on sbs 2003) which we think has been compromised.

First signs of something wrong was the hardware firewall disconnecting all outbound connections. there appears to be hundreds of emails going out through the postmaster account, however there is not traffic in the exchange queues. any ideas?

PS virus and spyware scans done
 
How do you know that 100's of emails are going out under the postmaster account?

I would suspect either
1. You're being used as a relay server.
2. A client has a virus and is the source of the mail.

But from what you say above about nothing in the queues I'd suspect number 1.

Make sure that relaying is disabled check out this guide:

Iain
 
or #3: You have been bombarded with a ton of spam messgaes to invalid addresses and your postmaster account is sending out NDRs (mostly bogus, as spammers typically use invalid Reply-To addresses)
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top