We have a client who is running exchange 2003, the mx records for mail point directly at this server and all has been working fine for the past few years, yesterday the server has been flooded with email (300,000) they normally process some where around 400 email per day, they are running Sophos puremessage and this is running without any faults being listed, how can i prevent this server from being bombarded, i have test for open relay and this is closed, i have made changes for reverse ndr attacks and all have no effect, any ideas guys???
blow is header from one of these emails :-
Thanks
Thread-Topic: =?Big5?B?oqqiqaRAue+qr6hrpGupyrdSvWclUk5EX0RJR0lUIFtTY2FubmVkXQ==?=
X-PMWin-Version: 3.0.0.0, Antivirus-Engine: 2.53.1, Antivirus-Data: 4.25E
Received: from collings-d496fa ([218.166.208.159]) by AVON.buav.org with Microsoft SMTPSVC(6.0.3790.1830); Wed, 16 Jan 2008 16:46:00 +0000
From: =?Big5?B?vEKlab33?= <fkp@82-70-105-132.dsl.in-addr.zen.co.uk>
Subject: =?Big5?B?oqqiqaRAue+qr6hrpGupyrdSvWclUk5EX0RJR0lUIFtTY2FubmVkXQ==?=
To: <w333@yahoo.com.tw>
Content-Type: text/html;
charset="Big5"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Date: Sun, 20 Jan 2008 00:47:45 +0800
Return-Path: <fkp@82-70-105-132.dsl.in-addr.zen.co.uk>
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.2826
Message-ID: <AVONnd333haDkrwmeth0000000b@AVON.buav.org>
X-OriginalArrivalTime: 16 Jan 2008 16:46:02.0865 (UTC) FILETIME=[47BB3E10:01C8585F]
PGh0bWw+dQ0KDQo8L2hlYWQ+DQoNCjxib2R5Pg0KDQoNCjxwPjxmb250IGNvbG9yPSIjMDA4MDgw
IiBzaXplPSI2Ij48YSBocmVmPSJodHRwOi8vb2xhc2ZhcS4xNjMudG8iPg0KPGZvbnQgY29sb3I9
IiMwMDgwODAiPrPMt3NEVkSl+rrQqqk8L2ZvbnQ+PC9hPjwvZm9udD48L3A+DQo8cD48Zm9udCBj
b2xvcj0iIzAwMDBGRiIgc2l6ZT0iNiI+PGEgaHJlZj0iaHR0cDovL2xvY2Fzcy4xNjMudG8iPg0K
PGZvbnQgY29sb3I9IiM4MDAwMDAiPrrrqva2Z7ZnsWrAyaqpPC9mb250PjwvYT48L2ZvbnQ+PC9w
Pg0KPHA+PGZvbnQgY29sb3I9IiMwMDAwODAiIHNpemU9IjYiPjxhIGhyZWY9Imh0dHA6Ly9ib3dl
YS4xNjMudG8iPg0KPGZvbnQgY29sb3I9IiMwMDAwODAiPq+4qvisRL/vrk3AXKqpPC9mb250Pjwv
YT48L2ZvbnQ+PC9wPg0KDQo8L2JvZHk+DQogICAgICAgICAgIA0KPC9odG1sPkoNCg0KDQo=
blow is header from one of these emails :-
Thanks
Thread-Topic: =?Big5?B?oqqiqaRAue+qr6hrpGupyrdSvWclUk5EX0RJR0lUIFtTY2FubmVkXQ==?=
X-PMWin-Version: 3.0.0.0, Antivirus-Engine: 2.53.1, Antivirus-Data: 4.25E
Received: from collings-d496fa ([218.166.208.159]) by AVON.buav.org with Microsoft SMTPSVC(6.0.3790.1830); Wed, 16 Jan 2008 16:46:00 +0000
From: =?Big5?B?vEKlab33?= <fkp@82-70-105-132.dsl.in-addr.zen.co.uk>
Subject: =?Big5?B?oqqiqaRAue+qr6hrpGupyrdSvWclUk5EX0RJR0lUIFtTY2FubmVkXQ==?=
To: <w333@yahoo.com.tw>
Content-Type: text/html;
charset="Big5"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Date: Sun, 20 Jan 2008 00:47:45 +0800
Return-Path: <fkp@82-70-105-132.dsl.in-addr.zen.co.uk>
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.2826
Message-ID: <AVONnd333haDkrwmeth0000000b@AVON.buav.org>
X-OriginalArrivalTime: 16 Jan 2008 16:46:02.0865 (UTC) FILETIME=[47BB3E10:01C8585F]
PGh0bWw+dQ0KDQo8L2hlYWQ+DQoNCjxib2R5Pg0KDQoNCjxwPjxmb250IGNvbG9yPSIjMDA4MDgw
IiBzaXplPSI2Ij48YSBocmVmPSJodHRwOi8vb2xhc2ZhcS4xNjMudG8iPg0KPGZvbnQgY29sb3I9
IiMwMDgwODAiPrPMt3NEVkSl+rrQqqk8L2ZvbnQ+PC9hPjwvZm9udD48L3A+DQo8cD48Zm9udCBj
b2xvcj0iIzAwMDBGRiIgc2l6ZT0iNiI+PGEgaHJlZj0iaHR0cDovL2xvY2Fzcy4xNjMudG8iPg0K
PGZvbnQgY29sb3I9IiM4MDAwMDAiPrrrqva2Z7ZnsWrAyaqpPC9mb250PjwvYT48L2ZvbnQ+PC9w
Pg0KPHA+PGZvbnQgY29sb3I9IiMwMDAwODAiIHNpemU9IjYiPjxhIGhyZWY9Imh0dHA6Ly9ib3dl
YS4xNjMudG8iPg0KPGZvbnQgY29sb3I9IiMwMDAwODAiPq+4qvisRL/vrk3AXKqpPC9mb250Pjwv
YT48L2ZvbnQ+PC9wPg0KDQo8L2JvZHk+DQogICAgICAgICAgIA0KPC9odG1sPkoNCg0KDQo=