A software update is available to help prevent the enumeration of Exchange Server 2003 e-mail addresses (899492)
The information in this article applies to:
- Microsoft Exchange Server 2003 Standard Edition
- Microsoft Exchange Server 2003 Enterprise Edition, when used with:
- Microsoft Windows Server 2003, Datacenter Edition
- Microsoft Windows Server 2003, Standard Edition
- Microsoft Windows Server 2003, Enterprise Edition
- Microsoft Windows Small Business Server 2003, Standard Edition
- Microsoft Windows Small Business Server 2003, Premium Edition, when used with:
- Microsoft Windows Server 2003, Datacenter Edition
- Microsoft Windows Server 2003, Standard Edition
- Microsoft Windows Server 2003, Enterprise Edition
Important This article contains information about how to modify the registry. Make sure to back up the registry before you modify it. Make sure that you know how to restore the registry if a problem occurs. For more information about how to back up, restore, and modify the registry, click the following article number to view the article in the Microsoft Knowledge Base: 256986 Description of the Microsoft Windows registry INTRODUCTION This article discusses a software update that you can install to help prevent the enumeration of e-mail addresses in your Microsoft Exchange Server organization. You can install this update if you run Microsoft Exchange Server 2003 on a Microsoft Windows Server 2003-based computer. MORE INFORMATION
Exchange Server 2003 provides a recipient filtering feature that can block an e-mail message that has been sent to a recipient that does not exist. The recipient filtering feature blocks the e-mail message by rejecting the recipient that does not exist. The recipient filtering feature blocks the e-mail message at the Simple Mail Transfer Protocol (SMTP) level. A side effect of this feature is that a malicious sender or a sender of unsolicited commercial e-mail can enumerate e-mail addresses that do exist by using a technique that is known as a
directory harvest attack.
If you click to select the
Filter recipients who are not in the Directory
check box when you configure the recipient filtering feature, directory lookup for recipients is enabled. If directory lookup is enabled, senders of unsolicited e-mail may discover valid e-mail addresses in your Exchange Server organization.
This software update adds a feature that you can use to delay the SMTP address verification responses for each invalid address that is submitted. This feature is referred to as the
tar pit feature. You can control the delay time by setting the value of the TarpitTime registry entry. By default, this feature is disabled. It takes more time and more money for an attacker to obtain
the global address list by using a directory harvest attack
against an SMTP server that has the tar pit feature enabled.
Note
Only anonymous connections are affected by the TarpitTime registry entry. Therefore, we recommend that you enable the TarpitTime registry entry only on the Internet-facing mail gateway servers.
Software update information A supported feature that modifies the default behavior of the product is now available from Microsoft, but it is only intended to modify the behavior that this article describes. Apply it only to systems that specifically require it. This feature may receive additional testing. Therefore, if you are not severely affected by the lack of this feature, we recommend that you wait for the next Microsoft Windows Server 2003 Service Pack that contains this feature. To obtain this feature immediately, download the feature by following the instructions later in this article or contact Microsoft Product Support Services. For a complete list of Microsoft Product Support Services telephone numbers and information about support costs, visit the following Microsoft Web site: Prerequisites
You must install this software update on a Windows Server 2003-based computer.
Restart requirement
You must restart the computer after you apply this software update.
Software update replacement information
This software update does not replace any other software updates.
File information
The English version of this software update has the file attributes (or later file attributes) that are listed in the following table. The dates and times for these files are listed in Coordinated Universal Time (UTC). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time tool in Control Panel. Windows Server 2003, 32-bit editions Date Time Version Size File name
-------------------------------------------------------
22-May-2004 00:19 6.0.3790.175 457,216 Smtpsvc.dll Windows Server 2003, 64-bit editions Date Time Version Size File name Platform
--------------------------------------------------------------------
21-May-2004 22:10 6.0.3790.175 1,177,088 Smtpsvc.dll IA-64 REFERENCES
For more information about the recipient filtering feature, click the following article number to view the article in the Microsoft Knowledge Base:
823866
How to configure connection filtering to use Realtime Block Lists (RBLs) and how to configure recipient filtering in Exchange 2003
For more information about Microsoft software updates, click the following article number to view the article in the Microsoft Knowledge Base:
824684
Description of the standard terminology that is used to describe Microsoft software updates
| Modification Type: | Major | Last Reviewed: | 10/21/2005 |
|---|
| Keywords: | kbWinServ2003preSP1fix kbExpertiseAdvanced kbQFE kbprb KB899492 kbAudITPRO |
|---|
|