Toon posts:

[Exchange] Uitleg smtp log

Pagina: 1
Acties:
  • 103 views sinds 30-01-2008
  • Reageer

Verwijderd

Topicstarter
Hey,


Wij hebben hier een exchange 2000 server draaien, waarvan ik sinds niet al te lange tijd de smtp log aan heb gezet om te controleren of wij niet misbruikt worden oid.

Op sommige tijdstippen is ineens de log 10x zo groot als op andere uren. Nou heb ik mij verdiept in open relay, en alles staat uit/disabled om een open relay te voorkomen. Nou vraag ik mij af wat het volgende inhoud:

code:
1
2
3
4
5
6
7
8
9
10
11
12
13
OutboundConnectionResponse SMTP SERVER - 25 - - 220+mta8.adelphia.net+ESMTP+server+
(InterMail+vM.6.01.03.02+201-2131-111-104-20040324)+ready+Tue,+7+Sep+2004+03:45:33+-0400 0 0 123 0 172 SMTP - - - -
OutboundConnectionCommand SMTP SERVER - 25 EHLO - server.cosmosis.local 0 0 4 0 172 SMTP - - - -
OutboundConnectionResponse SMTP SERVER - 25 - - 250-mta8.adelphia.net 0 0 21 0 328 SMTP - - - -
OutboundConnectionCommand SMTP SERVER - 25 MAIL - FROM:<spam@xxx.NET>+SIZE=1204 0 0 4 0 328 SMTP - - - -
OutboundConnectionResponse SMTP SERVER - 25 - - 250+Sender+<spam@xxx.NET>+and+extensions+(SIZE=1204)+Ok 0 0 66 0 500 SMTP - - - -
OutboundConnectionCommand SMTP SERVER - 25 RCPT - TO:<onbekend@yyy.net> 0 0 4 0 500 SMTP - - - -
OutboundConnectionResponse SMTP SERVER - 25 - - 250+Recipient+<onbekend@yyy.net>+Ok 0 0 38 0 766 SMTP - - - -
OutboundConnectionCommand SMTP SERVER - 25 DATA - - 0 0 4 0 766 SMTP - - - -
OutboundConnectionResponse SMTP SERVER - 25 - - 354+Ok+Send+data+ending+with+<CRLF>.<CRLF> 0 0 42 0 922 SMTP - - - -
OutboundConnectionResponse SMTP SERVER - 25 - - 
250+Message+received:+20040907074534.LQNA16676.mta8.adelphia.net@server.cosmosis.local 0 0 91 0 1297 SMTP - - - -
OutboundConnectionCommand SMTP SERVER - 25 QUIT - - 0 0 4 0 1297 SMTP - - - -


Het normale mail verkeer,(voorbeeld) ziet eruit als, mail van onbekend@xxx.net stuurt naar user@cosmosis.com


Maar in de logs die groter zijn dan standaard, zie ik heel veel van bovenstaande
FROM:<spam@xxx.NET>
TO:<onbekend@yyy.net>

Dus het lijkt alsof iemand mijn smtp server gebruikt om mail naar iemand anders te sturen. Is dit toch een vorm van relay, of iets anders? Want het lijkt alsof er geen mail naar @cosmosis.com wordt gestuurd, maar purr alleen de smtp server wordt gebruikt

[ Voor 16% gewijzigd door Verwijderd op 08-09-2004 13:56 ]


  • Tomsworld
  • Registratie: Maart 2001
  • Niet online

Tomsworld

officieel ele fan :*

Misschien es laten testen op bijvoorbeeld: http://www.ordb.org/submit/

"De kans dat een snee brood op een nieuw tapijt valt met de beboterde zijde onderaan, is recht evenredig met de prijs van het tapijt"


  • moto-moi
  • Registratie: Juli 2001
  • Laatst online: 09-06-2011

moto-moi

Ja, ik haat jou ook :w

exchange = windows software, dus een tikje van Non-Windows Operating Systems naar Software Algemeen

God, root, what is difference? | Talga Vassternich | IBM zuigt


  • Oceria
  • Registratie: Juli 2001
  • Laatst online: 10:26

Oceria

I've been in between....

Hier een link naar een pagina met tips om open relays te voorkomen/sluiten:
http://www.mail-abuse.com/support/an_sec3rdparty.html
(van de XS4ALL helpsite gekopiëerd).

Oceria doesn't know where this repeatbutton -repeatbutton is...


Verwijderd

Topicstarter
Volgens verschillende relay tests, en na een aantal relay verhalen gelezen hebben, oplossingen etc. Blijkt dat er geen open relay is, tenminste alle oplossingen zijn al eerder uitgevoerd, en alles relay tests geven aan dat er geen open relay wordt gedraaid.

Maar duid dit deel van de log toch op een open relay? Of posten jullie standaard om even te testen?

Verwijderd

het kan een authenticated user zijn die dit doet.
uit 324958 How To Block Open SMTP Relaying and Clean Up Exchange Server SMTP Queues
http://support.microsoft.com/?id=324958

Determine Whether an Authenticated User is Relaying
---------------------------------------------------

This section enables logging in the Windows Event Viewer such that any authentication attempts against the SMTP service (successful or failures) are logged in the application log.

1. Start Exchange Administrator.

2. Double-click "Servers".

3. Under "Servers", right-click <ServerName>, and then click
"Properties".

4. Click the "Diagnostic Logging" tab.

5. Click "MSExchangeTransport" on the left.

6. On the right, click "SMTP Protocol".

7. Under "Logging Level", click "Maximum".

8. Click "OK" to close "Server Properties".


If a remote user is authenticating against the Small Business Server computer as part of an operation to relay SMTP e-mail, you will see an event that is similar to the following in the application log:


Event Type: Information

Event Source: MSExchangeTransport


Event Category: SMTP Protocol


Event ID: 1708


Date: 8/13/2003


Time: 10:13:24 AM


User: N/A


Computer: SERVER

Description: SMTP Authentication was performed successfully with client <remote_computername>. The authentication method was <LOGIN> and the username was <company\username>.

In this case, if the relaying appears to come from a hacked account password, go to the Active Directory Users and Computers snap-in and delete the account, disable the account, or change the password on the account.

Verwijderd

Topicstarter
Verwijderd schreef op 08 september 2004 @ 14:37:
het kan een authenticated user zijn die dit doet.
uit 324958 How To Block Open SMTP Relaying and Clean Up Exchange Server SMTP Queues
http://support.microsoft.com/?id=324958

<knip>
Thnx, heb de auth user log aangezet, ik ben benieuwd

  • De Bij
  • Registratie: Juni 2004
  • Niet online
toch lijkt het op een open relay zo aan je log te zien, kan je mij het volledige log toemailen incl alle "echte" adressen e.d.? dan zal ik eens kijken of hij relayed of niet :)

[ Voor 5% gewijzigd door De Bij op 08-09-2004 17:04 ]

check mijn webshop!

Pagina: 1