Unknown user authenticating in my Email Server!

I have Exchange 5.5 SP4.  I noticed I have been acting as 
an open relay. While trying to correct the problem, I am 
getting the follwing Event ID when restarting the IMS:

2010
Connection from xxx.xxx.xxx.xx was authenticated (AUTH 
LOGIN) as \administrator

How do I stop this!?!
0
anonymous (74722)
4/28/2004 6:43:58 PM
exchange.admin 57650 articles. 2 followers. Follow

7 Replies
382 Views

Similar Articles

[PageSpeed] 51

Change the Administrator password!  Make it a complex password.

You can also disable the "allow authenticated users to relay" option if 
you do not need it.

-Brad Dinerman

Jason wrote:

> I have Exchange 5.5 SP4.  I noticed I have been acting as 
> an open relay. While trying to correct the problem, I am 
> getting the follwing Event ID when restarting the IMS:
> 
> 2010
> Connection from xxx.xxx.xxx.xx was authenticated (AUTH 
> LOGIN) as \administrator
> 
> How do I stop this!?!


-- 


______________________________________
Bradley J. Dinerman, MVP - Windows Server Systems
Chair, New England Information Security Group
http://www.neisg.org
0
Chair (3)
4/28/2004 7:13:28 PM
How do I rename the admin account?  I changed the password 
yesterday and it was already cracked!


>-----Original Message-----
>Change the Administrator password!  Make it a complex 
password.
>
>You can also disable the "allow authenticated users to 
relay" option if 
>you do not need it.
>
>-Brad Dinerman
>
>Jason wrote:
>
>> I have Exchange 5.5 SP4.  I noticed I have been acting 
as 
>> an open relay. While trying to correct the problem, I 
am 
>> getting the follwing Event ID when restarting the IMS:
>> 
>> 2010
>> Connection from xxx.xxx.xxx.xx was authenticated (AUTH 
>> LOGIN) as \administrator
>> 
>> How do I stop this!?!
>
>
>-- 
>
>
>______________________________________
>Bradley J. Dinerman, MVP - Windows Server Systems
>Chair, New England Information Security Group
>http://www.neisg.org
>.
>
0
anonymous (74722)
4/28/2004 7:53:23 PM
Jason,

Refer to 
http://www.spammarshall.com/SpamMarshallWeb/SMTPIntrusionDetection.jsp 
to prevent such attacks in future.

If these requests are coming for one or a defined set of IP, you can 
block them at your firewall.

Peter

Jason wrote:

> I have Exchange 5.5 SP4.  I noticed I have been acting as 
> an open relay. While trying to correct the problem, I am 
> getting the follwing Event ID when restarting the IMS:
> 
> 2010
> Connection from xxx.xxx.xxx.xx was authenticated (AUTH 
> LOGIN) as \administrator
> 
> How do I stop this!?!

0
anonymous (74722)
4/28/2004 11:14:06 PM
"Jason" <anonymous@discussions.microsoft.com> wrote:

>I have Exchange 5.5 SP4.  I noticed I have been acting as 
>an open relay. While trying to correct the problem, I am 
>getting the follwing Event ID when restarting the IMS:
>
>2010
>Connection from xxx.xxx.xxx.xx was authenticated (AUTH 
>LOGIN) as \administrator
>
>How do I stop this!?!

change the administrator password . . . and make the new password
sufficiently difficult to guess.

-- 
Rich Matheisen
MCSE+I, Exchange MVP
MS Exchange FAQ at http://www.swinc.com/resource/exch_faq.htm
0
richnews (7316)
4/29/2004 1:12:36 AM
Same problem but I've renamed the administrator account and changed the password numerous times. I also see someone logging in as Addionally, if I turn off routing no one can send to my domain
Any idea?
0
anonymous (74722)
5/11/2004 12:26:08 AM
rikki wrote:

> Same problem but I've renamed the administrator account and changed the password numerous times. I also see someone logging in as

Please provide specifics. Where and what exactly you see?

> Addionally, if I turn off routing no one can send to my domain!

Again, please post specific steps, as it seems that you are doing something different.

>
> Any idea?

0
kpalagin1 (1216)
5/11/2004 11:03:53 AM
"rikki" <anonymous@discussions.microsoft.com> wrote:

>Same problem but I've renamed the administrator account and changed the password numerous times. I also see someone logging in as Addionally, if I turn off routing no one can send to my domain!
>Any idea?

Did you change the password of a DOMAIN user or the LOCAL
administrator account? If you have an Exchange server that's not a DC
then you'll have the domain's builtin administrator account AND the
local administrator account to deal with.

Turning off routing should have NO effect on mail sent to your domain.
In fact, turning off routing will cause your IMS to accept mail for
ALL domains!

-- 
Rich Matheisen
MCSE+I, Exchange MVP
MS Exchange FAQ at http://www.swinc.com/resource/exch_faq.htm
0
richnews (7316)
5/12/2004 12:01:46 AM
Reply:

Similar Artilces:

Excel Mass Email
Does anyone know of anyway or program to do the following: We have Excel file that contains 3 columns- ID, password and email address. We need to email each ind email address their ID and password. Is there a program that we can use that will do this email merge? Thanks! Hi Jill Try this example on my site http://www.rondebruin.nl/mail/folder3/message.htm -- Regards Ron de Bruin http://www.rondebruin.nl "Jill" <anonymous@discussions.microsoft.com> wrote in message news:09b701c49fdc$32c52960$a601280a@phx.gbl... > Does anyone know of anyway or program to do the follow...

Entourage doesn't see emails or accounts
Version: 2008 Operating System: Mac OS X 10.6 (Snow Leopard) Processor: Intel Email Client: pop I had to reinstall Office 08 but first I tried to backup Entourages's files - like my emails - so they could be brought back in. I did not export them. I moved my copied files (identities, database, messages, etc.) back into the Microsoft User Data / Office 2008 Identities folder. But when I open Entourage, it's not seeing my accounts or the emails. Why not??? I can't import anything cuz like I said I didn't export. Please help!!! On 1/30/10 9:39 AM, in article 59bb1e57.-1@we...

Migrated new server OK
Hi, Several weeks ago I migrated all my Exchange 2000 mailboxes to a new Exchange 2003 server. Thanks to a lot of tips and help I received here, everything went smooth as glass. Could not have been easier. Now, I have my exchange 2000 server just sitting there doing nothing. It's also a domain controller. (I have another DC on a Windows 2003 server). What now? Can I safely take the W2K sever out of the domain and put it to rest? Do I have to uninstall Exchange 2000? Is there anything I have to do since it's a domain controller? For now it can stay up and running, but soon I wo...

Access 2003
Hi, I am trying to set up a database on Access that Monitors incoming and outgoing email traffic for specific group addresses in an Exchange Enviroment. This only needs to be a simple culmulative count with a date stamp. Not too sure how I would start this. Many thanks in advance for any help that can be given. My guess is to use MAPI to connect to and interact with the server. From there, there should be code available to read the traffic. "MaccaUK" wrote: > Hi, > > I am trying to set up a database on Access that Monitors incoming and > ...

Advanced Email Options
The options listed below are selected in the Advanced emails options of my Outlook application. - Automatic Name Checking - Suggest names while completing To, CC, and Bcc fields I've sent emails to certain email addresses in the past, and yet when I type part of their email addresses in the To, CC, or Bcc fields, they are not suggested or automatically completed, even when I tab to the next field. Can someone tell me what's causing this and what the fix is? ...

Problem sending emails from Outlook Express Ver6 NEVER MIND!
I am trying to use Outlook Express Ver6 instead of Eudora. I can't seem to send e-mails from it. When I send a test to myself I get the error: The message could not be sent because the server rejected the sender's e-mail address. The sender's e-mail address was (MY ADDRESS) .. Subject 'TEST', Account: 'incoming.verizon.net', Server: 'outgoing.verizon.net', Protocol: SMTP, Server Response: '550 5.7.1 Authentication Required', Port: 25, Secure(SSL): No, Server Error: 550, Error Number: 0x800CCC78 Can anyone suggest what is wrong? Must be something...

User Accounts
Help, We have setup several new users in active directory, with the create mailbox option selected. The tabs for the user are available in users and computers but do not have any data in them. We are running W2K and Exchange 2000. Inside of exchange, the mailbox's still have not appeared. It has been over 24 hours. Does anyone have any ideas on why? Thank you, Greg mailboxes will not appear in "mailbox resources" until they have received a piece of email or have been logged onto...is that what you mean? ""Greg Howard"" <noc@ciinc.com> wrote i...

CRM <-> Exchange Server Calendar
Is there any way in CRM 3.0 to link the User calendar to the matching Exchange calendar other that via the outlook client which I cant get to work ovr RPC HTTPS thanks in advance ...

Problem with the reconnection of a mailbox to a different user
Hello everybody, I have a problem with the reconnection of a mailbox, when I try to reconnect it to a different user. This is the scenario: 1) User A has a mailbox, I disconnect it. 2) Creation of User B 3) Reconnection of mailbox of user A to user B (I have tried not only with recovery center, but also directly through mailbox list section) No errors appears during theese steps, but when I try to create a new profile in outlook (I have created it only in the server, this is a test server), I see that the mailbox of user B (or the user B?) has not found! If I try to use Outlook Web Access, ...

How to send newsletter as HTML email
I can successfully create my newsletter in Publisher, choose to email it as a message, and it shows up perfectly in an email message. But now I have purchased an email program that allows me to paste in HTML to send to a large distribution list of subscribers. I want to copy my newsletter as HTML and send it via this program. I've tried saving the .PUB file as a single file web page (.mht file), then I open that file in my browser, view source, copy and paste the HTML code into my mailing list program and send it as an HTML email. However, when it is received in email, it is missi...

CRM Mailbox User on the 3.0 Demo Drive ?
Does anyone know what the CRM System Mailbox User is for the 3.0 demo drive? -Luke ...

Transferring email addresses from Access to Outlook address book
Is there a way of transferring a list of email addresses with their contact names from an Access Database Table to my Outlook? ...

Backup a users mailbox in Exchange 2003
We have recently terminated a couple employees, and I would like to make a copy of their mailboxes. How do I go about doing this? -- Chuck On Mon, 30 Oct 2006 06:36:02 -0800, chb12 <chb12@discussions.microsoft.com> wrote: >We have recently terminated a couple employees, and I would like to make a >copy of their mailboxes. How do I go about doing this? Exmerge is always a good option. What I normally do is open their mailbox on my outlook, then create a PST (name it the users name). Once the PST is created I copy the contents of their mailbox into the PST. From there you ...

Outlook / Exchange 2003 user connection problem
Ok, we are doing our Outlook configuration in a two step process first we add the Computer to the domain ( not the user ). Then we configure Outlook with the exchange server and user information. All of our users are created and have a default password. Problem is that when we go to setup Outlook we are only able to setup 2 - 5 computers a day. After we get 2 - 5 setup, when we try to install/configue another Outlook client we receive a message that say Cannot connect to Exchange server or Exchange server does not exist. But if we wait a day and go back to setting up Outlook again we are ab...

SMTP Error 452 4.3.1 Out of memory in Exchange Server 2000
After a successful Disaster Recovery of a Exchange 2000 Server (which is a Windows Domain Controller) - I installed Win 2000 Server + SP4, Exchange 2000 + SP3 and the Exchange Backup I get this strange error when I try to TELNET servername 25 and send the MAIL FROM:myself@mydomain.com 452 4.3.1 Out of memory The SMTP Service throws this error, but I can't find any hint in the event log. There is plenty of space on all disks and the permissions on "vsi 1" folders are also correct. Maybe an important hint: Prior to do the test, I installed the Trendmicro Client Server Messaging ...

SQL Server vs PostGress ,DB2 and Oracle
We are looking @ changing our Oracle DB with either SQL Server 2008 R2, PostGress or DB2. Does SQL SErver 2008 R2 support Pl/SQL? > Does SQL SErver 2008 R2 support Pl/SQL? No, you will need to alter the script "BillVAS" <BillVAS@discussions.microsoft.com> wrote in message news:3712F2DC-5BFB-49AC-A041-8D7433434475@microsoft.com... > We are looking @ changing our Oracle DB with either SQL Server 2008 R2, > PostGress or DB2. > > Does SQL SErver 2008 R2 support Pl/SQL? I seriously doubt that anyone, other than Oracle, supports PL/SQL. As...

E-Mails Bouncing from Server
E-mails that are sent to one of my users bounce intermittently, however, they bounce with the name of another user, i.e., an e-mail sent to johndoe@mail.com bounces back with a reply, i.e.: Your message did not reach some or all of the intended recipients. Subject: Technology Update Sent: 6/1/2005 3:07 PM The following recipient(s) could not be reached: Jane N. Doe on 6/1/2005 3:07 PM The e-mail account does not exist at the organization this message was sent to. Check the e-mail address, or contact the recipient directly to find out the correct address. <mail.mail.com #5.1...

Not able to send / recv Attachments in the Exchange Server
Hi, We are facing some probelms for receiving / sending Attachments with the Emails. Please reply either on above or qasimpurathil@hotmail.com / kasimpt@yahoo.com Regards, Kasim Does it go to the Outbox or error before that? Does it leave the Outbox? Do you get an NDR? Does the recipient get a mail with the attachment stripped? Is sending to local users affected? -- Hope that helps, Dan Townsend This posting is provided "AS IS" with no warranties, and confers no rights. Please do not send email to this address, post a reply to this newsgroup. Use of included script s...

Users name in 9.0
I have just updated my company to 9.0. I realize that the users name is now case sensitive. However, How can I see what the user name is stored as? I have user name "Jack" in the Tools - System - Users menu, but his case sensitive name to log in is "jack". If he tries to capitalize his name, the system gives him an error. I would like to see what the system is validating the users name to so that I can help users know what the correct user name is. To be clear, it is the id that the user enters when logging into GP, not the name. Are you saying that the id...

Regular expression validation for email
I might be doing something stupid here but I really need some help. Can someone please tell me why can't I get this xml to pass my validation when I use XmlValidatingReader? The XMLSpy seems to accept it. XML: <?xml version="1.0" encoding="UTF-8"?> <Address> <email>x.x@x.com</email> </Address> XSD: <?xml version="1.0" encoding="UTF-8"?> <xs:schema xmlns:xs="http://www.w3.org/2001/XMLSchema" elementFormDefault="qualified" attributeFormDefault="unqualified"> <xs:element nam...

saving emails
I need to reformat my hard drive but don't want to lose all of my emails and my contact list. Short of exporting everything individually, is there any way I can save my Outlook configuration so that everything isn't lost? Thanks! ...

Cassini server
From a couple of postings, I have come to know that the sales for outlook works under Cassini web server. Absolutely no idea what it is. Could anyone please explain me as to what Cassini is and how it works? Also, I was surprised to see that the web pages in CRM sales for outlook are published on localhost:2525. But I donot see any virtual directory created under IIS. And finally, supposing if I want to add a custom form in outlook CRM, then what is the process in sales for outlook? Do I need to create a virtual directory for this custom form? Otherwise, how would SFO identify the location ...

stuck email won't delete--holding up sync process
using an imap gmail account with WLM 14.0.8089.0726 on win xpsp3. there is a stuck outgoing message in the [Gmail] subfolder that will not delete. trying to delete it stalls WLM indefinitely (I left it overnight to find it still trying to delete the message). what's worse is that when syncing, upon reaching the [Gmail] folder containing this stuck email, syncing stalls out as well. I've gone through the program folders with windows explorer and can't seem to find that message to kill it that way either. I tried searching the forum for an answer but my searching...

Adding CRM User
Hi, I have installed MS Dynamics CRM 4.0 (Enterprise Evaluation Version) in a VM. Accessing the CRM with admin login works fine. When I try to login as other Active Directory user, I am getting the following error message. "No Microsoft Dynamics CRM user exists with the specified domain name and user ID. A Microsoft Dynamics CRM user record does not exist with the specified domain name and user ID." So, I logged in as admin and tried adding the active directory user. It is taking all the information related to the user from active directory. (User's Last Name etc). However...

Keeping mail on exchange server
I have an email account on an exchange server. I like being able to manage it via the web so that i can check my incoming mail, sent messages and also store attached files for viewing at remote locations. I also would like to be able to use this account in Outlook 2003. Is there a way to use this emal account in outlook and not have everything downloaded that i want to keep on the server? That's the way it works by default. Just make sure that your default storage location (Tools | E-Mail Accounts | View or Change E-mail Account | Deliver new mail to...) is set to the Exchange m...