Petri IT Knowledgebase Forums
 

Petri.co.il forums Home Forums Start Page Forums Frequently Asked Questions FAQ Member List Members List
Go Back   Petri IT Knowledgebase Forums > Messaging Software > Exchange 2000 / 2003
Petri.co.il is happy to award auglan the title of Most Valuable Member !!!
Register Calendar Calendar Search Petri IT Knowledgebase Forums Search Todays Posts Today's Posts Mark Forums Read

Notices

Spam from internal emails

Spam from internal emails

this thread has 6 replies and has been viewed 2730 times

Closed Thread
 
Thread Tools Search this Thread Display Modes
  #1  
Old 23rd February 2010, 22:58
AboveTheLogic AboveTheLogic is offline
Casual
Casual
 
 Join Date: Oct 2009
  6 month star 12 month star
 Location: Los Angeles
 Posts: 28
 Reputation: AboveTheLogic is on a distinguished road (10)
Default Spam from internal emails

Hi All-

I've done some searches and haven't found quite what I'm looking for- so I apologize if this is right under my nose... but...

I'm running Exchange 2003 on Windows Server 2003 and am in the middle of migrating to Exchange 2007 on Windows Server 2008.

The problem I'm running into (unrelated to the migration) is that users are receiving spam from clever spammers using the recipient's email address as the "from".

For example, my email address "user@mydomain.com" is getting spam FROM "user@mydomain.com".

I did some poking around and discovered that even though my server is not allowing email relaying (you need to authenticate to send email outside of mydomain.com), it does allow sending within my domain without authentication.

So, this allows anyone who has an email address of someone within my organization to send that person an email using their own email address --- or even some other email address as long as it ends with @mydomain.com.

How can I restrict this? I noticed that with some other email applications, this is still allowed although the server is smart enough to notice these email and put them in junk.

In my mind this is a major security hole, anyone with some words of wisdom or a direction to point me towards?

Thanks!
  #2  
Old 24th February 2010, 03:01
Sembee's Avatar
MVP Sembee Sembee is offline
MVP
MVP
 
 Join Date: Apr 2006
  6 month star 12 month star
 Location: Newbury, UK
 Posts: 6,201
 Reputation: Sembee has much to be proud ofSembee has much to be proud ofSembee has much to be proud ofSembee has much to be proud ofSembee has much to be proud ofSembee has much to be proud ofSembee has much to be proud ofSembee has much to be proud ofSembee has much to be proud of (1100)
Default Re: Spam from internal emails

Not a security hole at all. This is how SMTP email is designed to work.
All spam is spoofed and using the same domain as the recipient is one of the oldest spammers tricks. It is also hard to stop effectively, because of the amount of the "send to friend" which effectively spoof the email.

If you have an antispam application it should be dealing with these as any other spam. Ensure that you haven't white-listed your own domain (which is why the spammers do it). If you aren't using an antispam application then you will need to look at putting one in place.

There are no settings you can apply to a native Exchange server without third party software that will stop these kinds of messages - they are just spam.

Simon.
__________________
--
Simon Butler
Exchange MVP

Blog: http://blog.sembee.co.uk/
More Exchange Content: http://exchange.sembee.info/
Exchange Resources List: http://exbpa.com/
In the UK? Hire me: http://www.sembee.co.uk/
  #3  
Old 24th February 2010, 06:52
v-2nas's Avatar
v-2nas v-2nas is offline
Member
Someone to look up to
 
 Join Date: Jul 2008
  6 month star 12 month star
 Location: Singapore
 Posts: 722
  Send a message via MSN to v-2nas
 Reputation: v-2nas will become famous soon enough (80)
Default Re: Spam from internal emails

Hi

Check this setting,

SMTP Protocol > Properties > Access > Authenticate > Users
Under this only authenticated users SHUD have ONLY submit permission.
verify this option
__________________
Thanks & Regards
v-2nas

MCTS 2008, MCTIP, MCSE 2003, MCSA+Messaging E2K3, MCP, E2K7
Sr. Wintel Eng. (Investment Bank)
Independent IT Consultant and Architect
Blog: http://www.exchadtech.blogspot.com

Show your appreciation for my help by giving reputation points
  #4  
Old 24th February 2010, 11:22
FischFra FischFra is offline
Member
Here to help
 
 Join Date: Aug 2009
  6 month star 12 month star
 Location: Leipzig - Germany
 Posts: 432
 Reputation: FischFra will become famous soon enough (62)
Default Re: Spam from internal emails

Since you worte you are migrating to E2007: If you are using a Edgeserver you can implement the SPF record for your domain and activate the setting to reject failed SPF checks. This will effectivly stop those kind of spams.
  #5  
Old 25th February 2010, 02:26
AboveTheLogic AboveTheLogic is offline
Casual
Casual
 
 Join Date: Oct 2009
  6 month star 12 month star
 Location: Los Angeles
 Posts: 28
 Reputation: AboveTheLogic is on a distinguished road (10)
Default Re: Spam from internal emails

Thank you all very much for your replies, you have given me some great insight into how to solve this problem.

I had anti-spam installed on the 2003 installation but it expired, and since I'm migrating to 2007 I didn't renew. I adjusted some of the built-in anti-spam functions of Exchange 2003 but they are just not cutting it, obviously.

I plan to implement an edge server with our new 2007 setup, and I'm glad to hear that I can block these kinds of spams using it.

Regardless, I intend to shop around and can spend money if needed to implement a good anti-spam solution on the Exchange 2007 server when it goes live. Does anyone have any suggestions? We were running Trend-Micro Client Server Messaging Security on Exchange 2003 and it was OK, but not great.

Thanks again
  #6  
Old 27th February 2010, 21:39
Sembee's Avatar
MVP Sembee Sembee is offline
MVP
MVP
 
 Join Date: Apr 2006
  6 month star 12 month star
 Location: Newbury, UK
 Posts: 6,201
 Reputation: Sembee has much to be proud ofSembee has much to be proud ofSembee has much to be proud ofSembee has much to be proud ofSembee has much to be proud ofSembee has much to be proud ofSembee has much to be proud ofSembee has much to be proud ofSembee has much to be proud of (1100)
Default Re: Spam from internal emails

SPF records I find are close to useless. If you use them as a hard failure then you will find that you are dropping a lot of email. Edge servers are also a waste of time in my opinion, I can achieve almost the entire feature set with third party products for much less than an Exchange licence (the only that I cannot is aggregated safe senders list, but I wouldn't trust users to control that anyway).

Simon.
__________________
--
Simon Butler
Exchange MVP

Blog: http://blog.sembee.co.uk/
More Exchange Content: http://exchange.sembee.info/
Exchange Resources List: http://exbpa.com/
In the UK? Hire me: http://www.sembee.co.uk/
  #7  
Old 16th March 2010, 16:16
crobertson's Avatar
crobertson crobertson is offline
Casual
It's not a coincidence
 
 Join Date: Jun 2007
  6 month star 12 month star
 Posts: 80
 Reputation: crobertson is on a distinguished road (10)
Default Re: Spam from internal emails

I have come up with a simple way to fix this. Similar to keyword verification, set everyone to have a signature and they are required to include the signature on all emails. Even if they don't include their names, put in place a keyword.
Then require all emails from that domain require this keyword. I don't have exchange server, but we use this in email filtering.
__________________
I already know I'm not that bright. Please be constructive. Only give your 2cents if it helps. Don't be condesending or demeaning. It doesn't make you look smart. You just look like an arse.
Chris Robertson
The Computer Doctor
Closed Thread


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Cannot receive emails from out side and internal network in Exchange server 2003 sp2 sbsajjan Exchange 2000 / 2003 7 9th February 2010 01:27
Forcing internal emails to be delivered via internet jhzafrani Exchange 2000 / 2003 4 1st July 2008 15:18
sending emails from internal emails through one external email razar Exchange 2000 / 2003 1 30th January 2008 22:33
Internal Spam COSY Exchange 2000 / 2003 8 6th November 2006 10:35
Cannot Send and Receive Internal and External emails. poweredge4000 Exchange 2000 / 2003 3 9th August 2005 13:03


All times are GMT +3. The time now is 03:57.

Steel Blue 3.5.4 vBulletin Style ©2006 vBEnhanced
Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
 

Valid XHTML 1.0!   Valid CSS!

Copyright 2005 Daniel Petri