Mijn mailserver Exchange 2003 SP2 onder SBS2003 ligt al een aantal dagen onder vuur en ik krijg het niet gestopt!
Nu is het zo erg dat er 165.000 mailtjes in de queue staan en de SMTP server op hol slaat.
Ik heb al verschillende artikels gelezen over NDR attacks (In Exchange Server 2003 or in Exchange 2000 Server, the Exchange Server queues are filled with many non-delivery reports from the postmaster account because of a reverse non-delivery report attack).
Maar als het echt een NDR attack is dient de queue vol te staan met berichten van postmaster.
Maar er staan ook heel veel mailtjes in de queue naar van andere naar andere, zoals:
Van: "MR FRANK"<frankwuddah95@yahoo.com>
Naar: Envelope Recipients:
SMTP:barkkelly@rogers.com; SMTP:barkley3841@rogers.com; SMTP:baron.walden@hq.doe.gov; SMTP:barganier@peoplepc.com; SMTP:barilelandscape@charter.net; SMTP:barlinderand@alltel.net; SMTP:barnes_2003@sbcglobal.net; SMTP:barneygodfrey@sbcglobal.net; SMTP:baroo007@sbcglobal.net; SMTP:barker4939@rr.com; SMTP:barneskeshia@ymail.com; SMTP:bargainland_us@yahoo.com; SMTP:barj22@yahoo.com; SMTP:barkeeps77@yahoo.com; SMTP:barkerkelslie@yahoo.com; SMTP:barlou1@yahoo.com; SMTP:barnardwilliams@yahoo.com; SMTP:barnese51@yahoo.com; SMTP:barnesmickey28@yahoo.com; SMTP:barnessarah25@yahoo.com; SMTP:barnetk1@yahoo.com; SMTP:barnettm27@yahoo.com; SMTP:barneyflats99@yahoo.com; SMTP:barnums1000@yahoo.com; SMTP:baronicat@yahoo.com; SMTP:barrelracer4ever_03@yahoo.com; SMTP:barreraval@yahoo.com; SMTP:barrett.debbie@yahoo.com; SMTP:barrett_keisha@yahoo.com; SMTP:barrettr@brentwood-tn.org; SMTP:barnybtb@surfbest.net; SMTP:barfly101@aol.com; SMTP:barhan13@aol.com; SMTP:bariclaire@aol.com; SMTP:barkertxsranger@aol.com; SMTP:barmanuel@aol.com; SMTP:barnmolinari@aol.com; SMTP:barnzone@aol.com; SMTP:barrera174@aol.com; SMTP:barnes_t@kitchensolvers.com; SMTP:barreraanai@univision.com; SMTP:barney@dinosaur.com; SMTP:barrette@fvtc.edu; SMTP:barrettf@worldnet.att.net; SMTP:barretts4@earthlink.net; SMTP:baron.1@live.com; SMTP:baroninternational@microsodsi.net; SMTP:barneskasaundre@hotmail.com; SMTP:barouchmo@hotmail.com; SMTP:barney@luckeytrucking.com;
Maar ik heb gecheckt of mijn server Open Relay heeft, maar dit is niet het geval.
iemand enig idee hoe dit te stoppen!?
Nu is het zo erg dat er 165.000 mailtjes in de queue staan en de SMTP server op hol slaat.
Ik heb al verschillende artikels gelezen over NDR attacks (In Exchange Server 2003 or in Exchange 2000 Server, the Exchange Server queues are filled with many non-delivery reports from the postmaster account because of a reverse non-delivery report attack).
Maar als het echt een NDR attack is dient de queue vol te staan met berichten van postmaster.
Maar er staan ook heel veel mailtjes in de queue naar van andere naar andere, zoals:
Van: "MR FRANK"<frankwuddah95@yahoo.com>
Naar: Envelope Recipients:
SMTP:barkkelly@rogers.com; SMTP:barkley3841@rogers.com; SMTP:baron.walden@hq.doe.gov; SMTP:barganier@peoplepc.com; SMTP:barilelandscape@charter.net; SMTP:barlinderand@alltel.net; SMTP:barnes_2003@sbcglobal.net; SMTP:barneygodfrey@sbcglobal.net; SMTP:baroo007@sbcglobal.net; SMTP:barker4939@rr.com; SMTP:barneskeshia@ymail.com; SMTP:bargainland_us@yahoo.com; SMTP:barj22@yahoo.com; SMTP:barkeeps77@yahoo.com; SMTP:barkerkelslie@yahoo.com; SMTP:barlou1@yahoo.com; SMTP:barnardwilliams@yahoo.com; SMTP:barnese51@yahoo.com; SMTP:barnesmickey28@yahoo.com; SMTP:barnessarah25@yahoo.com; SMTP:barnetk1@yahoo.com; SMTP:barnettm27@yahoo.com; SMTP:barneyflats99@yahoo.com; SMTP:barnums1000@yahoo.com; SMTP:baronicat@yahoo.com; SMTP:barrelracer4ever_03@yahoo.com; SMTP:barreraval@yahoo.com; SMTP:barrett.debbie@yahoo.com; SMTP:barrett_keisha@yahoo.com; SMTP:barrettr@brentwood-tn.org; SMTP:barnybtb@surfbest.net; SMTP:barfly101@aol.com; SMTP:barhan13@aol.com; SMTP:bariclaire@aol.com; SMTP:barkertxsranger@aol.com; SMTP:barmanuel@aol.com; SMTP:barnmolinari@aol.com; SMTP:barnzone@aol.com; SMTP:barrera174@aol.com; SMTP:barnes_t@kitchensolvers.com; SMTP:barreraanai@univision.com; SMTP:barney@dinosaur.com; SMTP:barrette@fvtc.edu; SMTP:barrettf@worldnet.att.net; SMTP:barretts4@earthlink.net; SMTP:baron.1@live.com; SMTP:baroninternational@microsodsi.net; SMTP:barneskasaundre@hotmail.com; SMTP:barouchmo@hotmail.com; SMTP:barney@luckeytrucking.com;
Maar ik heb gecheckt of mijn server Open Relay heeft, maar dit is niet het geval.
iemand enig idee hoe dit te stoppen!?