Exchange Server email content control (internal, outbound, inbound)
Exchange Server email content control (outgoing, inbound)
Exchange Server email content control (internal, outbound, inbound)
Intelligent Message Filter (IMF) Whitelist / Safe Sender

Smart Action Triggers™

Elimination Spam

Address / NDR Mgmt

IMF Managment

Support is provided for:
Exchange 2007
Exchange 2003
Exchange 2000
Exchange 5.5
SBS 2003

Cluster environments support:
Active/Passive
Active/Active/Active

All service packs for Exchange Server are supported.

SecurExchange - > How To

How can I prevent a Directory Harvest Attack (DHA) and Spoofed NDRs on my Exchange Server?

Directory Harvest Attack Background:

Spammers use a technique called "directory attacks" to deliver email which can generate a high amount of NDR reports and ultimately chokes your bandwidth. There are many different techniques used but they typically fall into 1 of the following scenarios.

Directory attacks involve taking common given and surnames, generating addresses with many combinations of those names. For example taking "John" and "Smith" as common names, the resulting email addresses could be jsmith, johns, or john.smith to name only a few. By sending email with these combinations of multiple addresses results in an unusually high number of NDRs. However, the prime purpose of this type of spam is to determine which email addresses are valid within your Exchange Server organization.

Another manifestation of NDR attacks is due to the high number of spambots. Spambots are programs that have infested client PCs over the world and generate vast amounts of spam. These spam messages have automatically generated To and Sender addresses. When a spambot message is delivered to a target site, if the recipient address is not valid a NDR will be generated and sent to the Sender address. If the sender address happens to be your domain, then the NDR will be delivered to your server. The NDR is termed "spoofed" as the original message did not originate from your server/domain. This is also known as NDR BackScatter.

Nemx SecurExchange's Address Manager component, prevents Directory and NDR spoofing attacks by handling both scenarios. Directory harvesting attacks are handled by allowing a threshold to be set on number of un-resolveable recipients within an incoming email. Once the threshold is met, the message can be deleted or routed to a user or Public Folder. The SMTP session is then dropped, resulting in the "spammer" generating his own NDR on all addresses with no additional overhead on the part of your Exchange Server or your administrator. Spoofed NDRs are addressed by enabling a number of specific NDR rules. Once defined spoofed NDR matching particular characteristics can be trigger and any number of message actions may be invoked. Valid NDRs are not affected by SecurExchange's spoofed NDR logic.

 

Define a rule to handle spoofed NDR messages (BackScatter):

  1. From the Address Manager tab in the Non Delivery Report section, set the Enable setting
  2. In the Default Action field, select the appropriate message action (ie Delete Message, or any other available action)
  3. Press the Rules button.
  4. Enable the appropriate spoofed NDR rules - "Spoofed NDR", "Spoofed NDR - invalid address", "NDR - invalid address"
  5. Click Ok
  6. Click Apply

 

Define a rule to handle messages containing a high number of unresolveable addresses:

  1. From the Address Manager tab in the Header Filtering section, click Add
  2. In the Addressing Rule field, enter >>X, where X is the maximum number of unresolveable addresses permitted
  3. Select the appropriate Action.
  4. Enable Active
  5. Click Ok
  6. Click Apply

Need to add complete Anti-Virus protection from Internet email to your solution? Check out SecurExchange Anti-Virus!


Need to add virus protection to your solution?
Check out SecurExchange Anti-Virus

More About This Product: Fact Sheet | FAQS | Download | Feature Matrix

Still not sure which solution is right for you? Find out more about our SecurExchange family of products, compare products through a feature matrix, or view some of our most Frequently Asked Questions, or email info@nemx.com

 

Internal corporate email outnumbers all other messages 8:1

Appliances and managed services monitor only 15% of total corporate email traffic


Straight "plug & play" add-in to Microsoft Exchange Server 2007, 2003, 2000, 5.5 or Small Business Server 2003

A highly intelligent and intuitive new tool in the fight against spam and pornographic content

Uses "fuzzy logic" and natural language processing to determine the concept of an email

White List Exchange's Intelligent Message Filter (IMF) by Domain, sub Domain, country Domain, or individual address

Built-in multiple RBL and SURBL database support

Use techniques like reverse DNS lookup (RDNS) and IP and codepage country of origin determination to block non standard and out of country SMTP traffic

Reduce the amount of energy in dealing with Exchange Server NDR reports (valid or spoofed)

Easy to administer and manage with self-updating policies


 

Copyright 1996-2007, Nemx Software Corporation, All Rights Reserved. All trademarks used or referred to on this site are the
property of their respective owners. No materials on this site may be reproduced, altered, or further distributed without Nemx's prior written permission.