Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


October 09, 2003

A New Kind of Attack


RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints
Or get the Monthly Online Pass—only $5.95 a month!

A worrisome new kind of attack is making the rounds on the Internet. This new threat isn't a worm like SoBig or Slammer, and it isn't a virus like Swen--it's an insidious spam attack that victimizes innocent Exchange Server systems. And this attack is succeeding far more often than it should.

Spammers are scanning the Internet looking for SMTP servers. These spammers use retrieved banner information to identify Exchange servers, then use the SMTP service to mount brute-force password-guessing attacks against well-known accounts on those servers. That's right: Instead of attacking the increasingly well-defended Windows remote procedure call (RPC) services that most organizations use for logon authentication, this attack sends a barrage of SMTP AUTH LOGON commands until one succeeds.

"But wait a minute," you say. "Exchange Server 2003 and Exchange 2000 Server have relaying turned off by default!" Yes, they do--for unauthenticated users. But if a spammer manages to snag an authenticated user's credentials, the spammer can authenticate to your server and use it to blast out millions of spam messages. As a consequence, your server (and possibly your entire IP block) will likely end up on a variety of blacklists--and you'll probably receive a flood of angry messages from irate spam recipients. To make matters worse, all this activity probably will fill your queues and transaction logs, slowing your server's performance.

This attack's dastardly nature is worsened by the fact that the attack is mostly invisible unless you've turned on auditing for account-access events. The SMTP log that the Microsoft IIS SMTP component maintains doesn't record the use of SMTP AUTH, so you can't look for a sudden spike in the number of AUTH requests to indicate that you're under attack. Your first warning sign might be that your server starts getting waves of spam-generated nondelivery reports (NDRs). Fortunately, protecting your servers against this attack is a simple process.

First, make sure that your administrator accounts have strong, complex passwords with more than 15 characters that are a mix of letters, numbers, and symbols. (When a password has 16 or more characters, Windows can't locally store the password's easily-cracked LM hash.) Other user accounts also should have complex passwords, but protecting your privileged accounts against brute-force password guessing is especially important.

Second, if you don't allow relaying, consider turning it off completely on all external-facing servers. If you do allow relaying, I suggest you reconsider your decision. For example, if you allow relaying to support external POP users, consider whether you could accomplish this task another way (e.g., by using the users' ISPs).

Third, consider disabling both basic and Windows integrated authentication on any SMTP virtual server that faces the Internet. Doing so prevents password-guessing attacks, but it also prevents users from authenticating before sending email. If you must leave this feature enabled, make sure that you also enable account-object auditing and regularly monitor the Windows event logs for long series of event ID 528, which failed logon attempts generate.

Fourth, if you use an Intrusion Detection System (IDS), configure it to watch for failed SMTP authentication requests (i.e., tell it to look for the text "535 5.7.3 Authentication unsuccessful" at offset 54 in packets on TCP port 25). This warning will alert you to an attempted attack.

Microsoft knows about this type of attack and will probably take measures to protect against it at some point. Until then, keep a careful eye on your servers to make sure they aren't being attacked. (And thanks to Andy Webb, who first brought this subject to my attention.)

End of Article



Reader Comments
What about Exchange 5.5? How can these events be monitored?

CSLEBL October 14, 2003


That's one of the reasons why I recommend to everybody not to expose an Exchange server SMTP service directly. *Always* put an edge server in front of it with a plain SMTP service like SendMail, PostFix etc. and let it handle all incoming SMTP. It also offers the additional value of running anti spam software like SpamAssassin (FREE!) to keep up with all the spam crap coming in.

Putting Exchange Server to the Internet == BAD!!!

John Meyers November 19, 2003


Thanks for the article. I have been receiving a few NDR's that have worried me. At least I now know that there may be something in them - more investigation required.

TIA

Paul Bigwood November 25, 2003


We firewalled access to our exchange server and both the server and remote clients use AuthSMTP - http://www.authsmtp.com

They let me relay from both ISP's we use and have extra security (sender authentication) - as as you say making it near worthless for spammers.

Oh as an extra precaution they also virus scan outgoing mail! ;)

Anonymous User October 22, 2004


We firewalled access to our exchange server and both the server and remote clients use AuthSMTP - http://www.authsmtp.com

They let me relay from both ISP's we use and have extra security (sender authentication) - as as you say making it near worthless for spammers.

Oh as an extra precaution they also virus scan outgoing mail! ;)

Anonymous User October 22, 2004


We firewalled access to our exchange server and both the server and remote clients use AuthSMTP - http://www.authsmtp.com

They let me relay from both ISP's we use and have extra security (sender authentication) - as as you say making it near worthless for spammers.

Oh as an extra precaution they also virus scan outgoing mail! ;)

Anonymous User October 22, 2004


We firewalled access to our exchange server and both the server and remote clients use AuthSMTP - http://www.authsmtp.com

They let me relay from both ISP's we use and have extra security (sender authentication) - as as you say making it near worthless for spammers.

Oh as an extra precaution they also virus scan outgoing mail! ;)

Anonymous User October 22, 2004 (Article Rating: )


We firewalled access to our exchange server and both the server and remote clients use AuthSMTP - http://www.authsmtp.com

They let me relay from both ISP's we use and have extra security (sender authentication) - as as you say making it near worthless for spammers.

Oh as an extra precaution they also virus scan outgoing mail! ;)

Anonymous User October 22, 2004 (Article Rating: )


We firewalled access to our exchange server and both the server and remote clients use AuthSMTP - http://www.authsmtp.com

They let me relay from both ISP's we use and have extra security (sender authentication) - as as you say making it near worthless for spammers.

Oh as an extra precaution they also virus scan outgoing mail! ;)

Anonymous User October 22, 2004 (Article Rating: )


Why is Exchange soo bad?

Just ensure the Internet connected SMTP 'virtual server' has authentication disabled. Do allow relaying based on the IP address. (Of course a firewall should ensure private IPs don't come from the Internet, no matter your installation).
Exchange 2003 also supports DNS-based block lists.

Besides, SpamAssassin runs on Exchange too (FREE, of course).

Anonymous User October 23, 2004


 See More Comments  1   2 

You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
The Memory-Optimization Hoax

Don't believe the hype. At best, RAM optimizers have no effect. At worst, they seriously degrade performance. ...

Remote Control Software

Control remote machines from home or the office. ...

WinInfo Short Takes: Week of July 21, 2008

An often irreverent look at some of the week's other news, including an iPhone 3G defeat, 180 million copies of Windows Vista in the wild, Microsoft earnings some more Yahoo silliness, Wii vs. Xbox 360, EU vs. Intel, AMD ousts its CEO, and so much more ...


Security Whitepapers Anti-Virus Is Dead: The Advent of the Graylist Approach to Computer Protection

Getting the Job Done: Comparing Approaches for Desktop Software Lockdown

Instant Messaging, VoIP, P2P, and games in the workplace: How to take back control

Related Events Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.


ADS BY GOOGLE SPONSORED LINKS FEATURED LINKS

Shortcut Guide to SQL Server Infrastructure Optimization
With right tools and techniques, you can have a top-performing SQL Server infrastructure without having to cram your data centers so that they're overflowing. Download this eBook to learn how.

WinConnections Conference Fall 2008
Don’t miss the premier event for Microsoft IT Professionals in Las Vegas, November 10-13. Register and book your room by August 25 and receive a FREE room night (based on a three night minimum stay).

Become a fan of Windows IT Pro on Facebook!
Join us on Facebook and be a fan of Windows IT Pro!

Continuous Data Protection and Recovery for Exchange
Read this white paper to learn about Continuous Data Protection (CDP), Exchange 2007's local continuous replication and cluster continuous replication features.

Rev Up Your IT Know-How with Our Recharged Magazine!
The improved Windows IT Pro provides trusted IT content with an enhanced new look and functionality! Get comprehensive coverage of industry topics, expert advice, and real-world solutions—PLUS access to over 10,000 articles online. Order today!

Tips to Managing Messaging
Discover three fundamental mail and messaging management services - security, availability and control services - and how you can implement them in a Microsoft-centric mail and messaging environment.

Get It All with Windows IT Pro VIP
Stock your IT toolbox with every solution ever printed in Windows IT Pro and SQL Server Magazine plus bonus Web-exclusive content on hot topics. Subscribe to receive the VIP CD and a subscription to your choice of Windows IT Pro or SQL Server Magazine!



Drag & Drop Data Mapping Tool
Try this award-winning data mapping, & transformation tool that supports multiple databases, flat files, Web services, EDI, Excel 2007, & more! Free trial for 30 days!

Overcome bloated Windows file systems
Crossroads FMA delivers powerful yet inexpensive data migration

Bandwidth Monitoring Tool from SolarWinds
Identify largest bandwidth users in seconds. Get the free download now.

Speed Deployment of Vista and Microsoft Office
Read this white paper to learn how you can maximize your Vista and Office investments while lowering costs and increasing efficiency.

Integrated Virtualization Done Right
Download this white paper on server virtualization to begin improving resource utilization and lowering operating costs.

Order Your Fundamentals CD Today!
Gain an introduction to Exchange, learn server security requirements, and understand how unified communications can play a role in your messaging strategies with this free Exchange CD.

KVM over IP Solutions
Learn about a KVM over IP solution that is specifically designed to meet the needs of the distributed IT environment.
Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound
IT Library Technical Resources Directory Connected Home Windows Excavator SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing