Advertisement
Promo

Security threats Toolkit

Exchange flaw leaves systems 'open to spammers'

Published: 17 Nov 2003 11:05 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Administrators of email systems based on Microsoft's Exchange might have spammers using their servers to send unsolicited bulk email under their noses, a consultant warned this week.

Aaron Greenspan, a Harvard University junior and president of consulting company Think Computer, published a white paper Thursday detailing the problem, discovered when a client's server was found to be sending spam. Greenspan's research concluded that Exchange 5.5 and 2000 can be used by spammers to send anonymous email. He says even though software Microsoft provides on its site certifies that the server is secure, it's not.

"If the guest account is enabled [on Exchange 5.5 and 2000], even if your login fails, you can send mail, because the guest account is there as a catchall," he said. "Even if you think you've done everything [to secure the server], you are still open to spammers."

The guest account is a way for administrators to let visitors use a mail server anonymously, but because of security issues, the feature is generally not enabled. Exchange servers that had been infected by the Code Red worm and subsequently cleaned will still have the guest account enabled, Greenspan said.

There are dozens of messages -- with subject lines such as "Open relay problem" and "We are sending spam?" -- on Microsoft's Exchange Administration newsgroup, sent by information system managers who haven't been able to staunch the flow of spam from their servers.

Microsoft, however, said the problem is relatively minor and that the company hasn't had many complaints.

"This particular method of sending spam relies on specifically configured servers or is leveraging weaknesses in the protocol itself," the software giant said in a statement issued in response to questions from CNET News.com. "The fact is that Microsoft has not received a lot of calls from customers that have experienced problems detailed by Think Computer."

Moreover, the company said the issue doesn't affect the latest version of the software, Exchange Server 2003.

Greenspan, however, argued that the problem has accounted for a large amount of unsolicited email. He estimates that at least 100,000 messages spammers in China sent went through his client's server before he stopped the problem. He added that the issue is causing headaches for Exchange administrators.

"It is really inexcusable for a company that claims security is its top priority," he said.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
79 out of 164 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

Official Organizations Losing Data

How does this article from earlier today make you feel? How many more government, health service, or military officials are going to lose pen drives, DVDs, USB hard disks and even entire... More

2 comments

Twitter hack was DNS redirect

Twitter has said an attack on Thursday which took the site offline for many users was the result of a DNS redirect. A group calling itself the Iranian Cyber Army redirected users... More

1 comment

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters