Smtp Service compromised?
Hey,I have an SMTP service on a production Windows Server 2003 box that I think has been compromised. In the eventlog I'm getting a lot of messages like this:Event Type:WarningEvent Source:smtpsvcDescription:Message delivery to the remote domain 'fabietto' failed for the following reason: Destination server does not exist.The domains that it shows aren't of users in my database so I know that emails should not be sending to these domains, hence my thinking that someone has compromised the SMTP service and isusing itto relay spam messages to the masses.In Authentication, I have Anonymous Access and Integrated Windows Authentication checked. In Relay I have Only the List below selected, then I have no IPs added, and at the bottom I have checked "Allow all computers which successfully authenticate to relay, regardless of the list above." I have Anonymous Access checked because this server also uses POP to receive incoming mail and if I uncheck Anonymous Access then people can't send email to my domain, it gives them a 530 Authentication Required error.Is there something I'm missing that I should be locking down here?Thanks,Justin
June 8th, 2009 9:54pm

Hi, Regarding this SMTP service issue, I suggest that you post to the Exchange Server forum. The support professionals there are better qualified to assist you. Exchange Server forum http://social.technet.microsoft.com/Forums/en-US/category/exchangeserver Thanks.
Free Windows Admin Tool Kit Click here and download it now
June 10th, 2009 6:01am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics