Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Tuesday, September 11, 2007

Need full access for all users’ mailboxes in Your SMTP mail organization



Exchange 2003 administrators have explicit denied access to user's mailbox, except their own. This was not the case before. Let's think a scenario for some reason you need to have full mailbox access to all users mailbox. (You don't have to tell me, why) how can this be achieved. Below I will illustrate how an Exchange administrator may achieve this goal. You can permit yourself to see everyone mail box on the entire company easily. Below register hack is for a user profile, so you are just making changes on the account you have logged in.

  • Copy and paste the code into notepad
  • Click file Save
  • Name the file ShowSecurityPage.reg
  • Click on save as type, change it to all files
  • Save it on your desktop as ESMShowSecurity.Reg, and double click on it to make the changes
  • Click OK two times
  • Open ESM now you will see security tab.


 

Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Exchange\EXAdmin]

"ShowSecurityPage"=dword:00000001


 

Now go to ADUC create an account, to be used to look at all users mailbox. Let's say we will create account called "MailMaster" Now we will go back on top of ESM and add this account there and give full permissions, which will inherit all the way down to your entire mail organization. Great now we have an special account which has full permissions on all mail enabled object, including send as receive as

Go to your OWA now and log on with your user ID and password, such as Https://Mail.Smtp25.org/Exchange, OWA will ask you your user name and password before you see your own mailbox. Go ahead supply your credentials and login.

After you log in all you need to do is add at the end of your Browser the user ID of the user's mailbox you wish to visit. Let's say you want to see, Brad's mail and his NT Id is Brads, After last slash in the address bar with browser add simply brads ID, OWA will ask you( Now you are telling OWA open Brad mailbox )

Who you are, and you will be "MailMaster", which has FULL permission on any mail enabled object, type the password for this account, OWA will gracefully open up and show you Brad's mailbox, while Brad is logged in on to his mailbox you will be a shadow looking at all his E-mails and he will have no idea, what is going on

Be careful privacy is serious issue and do not misuse your knowledge

Best,

Oz ozugurlu

Wednesday, August 22, 2007

Change FQDN name on EHLO/HELO




Problem:

My email server has been listed at CBL (Composite Blocking List) due to an improper HELO response.  My outbound IP Address resolves to mail.mydomain.com at our authoritative DNS.  When certain servers do an EHLO/HELO check for spamming, my email server returns servername.domainname.local (my internal domain name).  How can I get my Exchange Server 2003 to respond with my DNS listing of mail.domain.com??

Solution:

  • Open ESM drill down to
  • Administrative groups
  • Servers
  • Your server
  • Protocols
  • SMTP
  • Virtual Server, Properties

Deliver, and Advance, under Full qualified domain name, (VSEX1.smtp25.org) replace the entry with your public host record of your mail server FQDN (mail.smtp25.org), click Check DNS to make sure it is valid.

Stop and restart your Exchange Virtual server, now if you telnet into your server on port 25 you will get SMTP banner as mail.smtp25.org

Best,

Oz Ozugurlu

Thursday, July 5, 2007

Everyone" group has been granted "Send As" and "Receive As" rights



Here is the scenario, all o f a sudden you discover everyone can see everyone's mailbox on your SMTP domain. Full explicit permissions on the object (everyone), including Receive As permissions seems to assign everyone. Everyone" group has been granted "Send As" and "Receive As" rights I have seen this, may occur after migration scenarios.

To see the Security Tab on ESM, (Exchange system manager) copy the code below and paste into a notepad and save it as "ShowSecurityPage.reg" on your desktop. Go ahead double click on it to make the register changes.

  • Copy and paste the code into notepad
  • Click file Save
  • Name the file ShowSecurityPage.reg
  • Click on save as type, change it to all files
  • Save it on your desktop, and double click on it to make the changes

Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Exchange\EXAdmin]

"ShowSecurityPage"=dword:00000001





Best,

Oz Ozugurlu

Wednesday, May 23, 2007

A lot of spam targeted at my Exchange server




I have seen more often these days, people asking about how to stop spammers, or make Exchange a little bit stronger for defending itself for this endless spam war. Receiving blank messages or spam makes a business valuable time and resources waste, and top of that we have to deal with angry managers and unhappy users. I have decided to put some notes together for those who need some guides in order to achieve goal of making Exchange a little bit more secure and strong.. I have already mentioned about Exchange 2007 and new Role based administration model, and how strong 64Bit Exchange is in my several previous blogs, read it here you will learn a lot and hopefully move into Exchange 2007 as soon as possible. Especially read and do research about Edge transport server and Exchange ForeFront technologies.

Goals and Objectives listed below.

  • Use IMF Microsoft Intelligent Message Filter, it is FREE
  • Use antivirus and spam software with your exchange server, I am little bias and like Trend Micro in this matter, Trend is doing great job, if you are corporate than you may want to implement hardware solution, Iron port, Barracuda, end etc.
  • Enable Sender filtering
  • Enable Filter messages with blank senders
  • Enable Drop connection if address matches filter
  • Add your own domain (whole domain into Block list) I know this will sound weird (- : This won't cause any mail interruption, even though it sounds like it, basically it will stop someone is spoofing a valid address from your company and sending message back inside your Authoritative SMTP domain and making it look like it came from inside
  • Make sure you do not have application within your network; this might break some of the applications which are relaying exchange server to send inbound or outbound e-mails (payroll, or Application server etc) They sit outside of your SMTP domain and send mail back to your SMTP domain, by using an internal SMTP address, even though they are not autherative for your SMTP Domain.
  • Enable Recipient filtering
  • Enable Filter recipients who are not in the Directory
  • Add regularly spammers either Whole domain (@smapmer.com) or single e-mail address (smapmer@spam.com) into block list
  • Download Exchange tools and RUN again your server to make sure it is secure and healthy and you followed Microsoft best practice
  • Go for Exchange 2007 if it is possible it is much stronger and secure if I compare to any other version of Exchange servers, you can eliminate third part Spam solution and even Save $$$$$$ for your company , while bringing the art of state messaging system into your organization, lower the TCO

We are almost done. A good exchange administrator should check to make sure Spam software is getting updated; as well as file signature is up to date. You don't want to wake up when your boss come to office and telling at you, what is going on I am getting a lot of spams. Prepare a good documentation of your own environment; make sure your e-mails Queues are not growing up fast. Turn on some of the basic maintenance Alerts build in exchange. Watch a lot of Webcast/Podcast Exchange 2003 and 2007 series from TechNet.

Also Visit Harold Blog Site

Best Regards

Oz Ozugurlu

Thursday, April 26, 2007

Using RUNAS and Securing Exchange Daily Task

Here in this this article i will write about, one of the most I have needed to work on daily basis, Remote execute program with this tool It is possible to run "CMD" window on the remote server, as long as you have the proper rights and you logged into a domain. Speaking of daily Exchange and AD admin life, I have realized many of the administrators won't work in secure environment, they log into Domain with Domain administrator privileges and they go to internet and perform daily task with that. When it comes to s security, we more complain about windows is not being secure, but I think we need to look at ourselves and use the windows right way so that windows will provide secure environment for work daily routine. I will demonstrate a secure way of working with Windows and getting the entire daily job done without problems

First thing you will need to have two accounts in a Domain, let's say we will create an account named oz

First Account Name

oz

Domain User Mail enabled

Second account

ZZ-oz

Domain administrator, Enterprise administrator No mailbox


Now log into your work station with domain User account, this account is to be logged into system all he times.

We will not log into systems with our ZZ-oz account, we will use RUNAS and get the job done with ZZ account privileges when we need it

After you logged in (remember you are a Domain user now, CANNOT give any damage to anything pretty much, try going to device manager and deleting a device, windows will deny your request.)

Now open a notepad and type


runas /user:archq\zz-oz cmd.exe Change my name into your account name

Click Save, File Name RunAS.bat Save Type as, all files

And save it on your Desktop. Now when you double click on it DOS window will open up and ask you to type your password, ones you successfully type your password ( pay attention this is Domain admin password)

A window will open up with Domain admin privileges.

Now you are still logged in as a domain user, but you have a window in from of you (CMD.EXE) which is running with your domain admin privileges.

So what can you do with this?

Go ahead download,

Windows 2003 Support tools so that you can manage AD with it.

Download Here

When it gets to installation all you need to do, is drag the program into CMD window, and hit enter on the keyboard, the setup installation program will be executed with your Domain administrator privileges

It is kind of cool.


Now after installation if you go to rum command and type

Dsa.msc ADUC snap in wont lunch, will lunch but you won't be able to perform any admin task,

Why because you executed it with your domain user credential so windows know you are a user, and have no business of seeing the ADUC snap in.

However, if you type the same command into CMD window which is running with Domain administrator privileges, ADUC will happily open up, and you can perform any task as you wish as Domain Administrators

Now you got the idea, go ahead and play with other thing,

TIPS: you don't have to remember all the short cut abbreviations, you can simply drag and drop anything into CMD windows running under Domain administrator privileges,( don't forget to press on enter) this will execute the program with domain admin credential.

I open ESM several times just like this, during a working day.

Now you get the idea, working secure and smart is up to you. Making windows and managing exchange is up to you as well.

Now, one of the cools thing Windows Sysinternals (Free) is to get the program called

Psexec

Download the ZIP the suite of the entire tools form my Blog site

http://smtp25.blogspot.com/

What is this Psexec tool? Lets you execute processes on other systems

This is great and always what we wanted to do. Now unzip this and save it to your System32 directory below on your Desktop.


%homeDir%\system32/

Paste all the files (Entire Suite) into this directory

Go back to administrator CMD window. Don't forget you need to be in Domain Environment.

Here is the situation we need want to open Remote CMD window on our exchange server while we are logged into our workstation

Exchange serve name is BIOBR2

So we will type this command into Domain administrator CMD window

Type below command

Psexec \\biobr2 cmd.exe

On the command line if you type hostname, you will noticed you are on BIOBR2 server and If you do IP config you will get the IP configuration of the remote server

Now, you can type there, Services.msc, Compmgmt.msc Notepad You can open internet explorer, remote console user will see internet explorer will open up miserly on the server. There are more cool programs in your system32 directory, along with Psexec.exe which is fun to play with

Special thanks to Ron Buzzon, who is my friend future Exchange and AD MVP candidate

Best Regards,

Oz Ozugurlu