Help - Search - Members - Calendar
Full Version: Windows 2000 Server Exchange/SMTP Problem!
Neowin Forums > Windows Support > Windows NT4/2000/2003/2008 Server
Ilyes
I am having a really weird problem.

I am running Windows 2000 Server Sp3 and Exchange 2000 and trying to run SMTP. For some reason, after I start running it for a while, I get like 100 connections to the internet to different SMTP serers around the world? It looks totally like some type of hack or a virus or something?

I am going to try updating Exchange....but in the meantime, does anyone know what could be causing this?

Thanks!

- Jimmy
LPC
Are they incoming or out going connections ?
BudMan
Exactly are they incoming or outgoing? Look at your queues! I would say your server is busy sending SPAM! wink.gif Whats the IP of this server? Have you checked to see if its open to relay? I would guess its listed as a open relay.. Whats the IP?
Ilyes
The connections are all mostly outgoing, TWO of them are incoming. That's what is so fishy about this. And yes, the computer is open to relay to everyone....

Thanks for your help!

Edit: Also, I checked the queue and it was really full.

PS- Only 2 people use this SMTP server...
Ilyes
omg...I just checked the queue....17,000 emails!!!!!!!!!!!!!!!!!!!! See, this looks totally like some kind of hack or something?
primortal
of those 2 pcs, have you scaned them for virus or spyware? It possible that either or both of those machines are zombies and sending spam. Or your exchange server is and open relay to the outside and other people are using it for sending spam
Ilyes
The two machines I am referring two are two random connections from the internet...
LPC
Ya is running an open relay ... prepare to get black listed all over the place and your ISP might get a stop on !

Sort it out here.
Ilyes
I updated the Exchange server to Service Pack 3 and some other hotfixes and I disabled relay....
Ilyes
Now I can't send ANY emails....I have it set just like that guide says...
BudMan
Dude I PM'd you -- yeah looks like you got it locked down so nobody can send mail - get denied by policy, you need to set it up so your local machines can send mail, etc.. And you have to setup the domain you accept mail for, etc..

Let me know what domain your suppose to hosting mail for, etc.. since I did not see a reverse for the IP you sent me (only one of them was listening on 25) And quite a few domains will NOT except mail from you when you do not have a reverse, etc..
Ilyes
Lotus Domino....

I replied to your PM
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.