General discussion

  • Creator
    Topic
  • #2311565

    Exchange – Able to view all users mail

    Locked

    by tomf ·

    Greetings,

    I am a SysAdmin of several machines, one of our machines was hacked recently. I can now goto the M:\ (Exchange) drive and view ALL the users mailboxes in the MBX directory. On a different system that was not hacked I am unable to viewtheir mail (And rightfully so).

    My question is this, how did the hacker open those permissions? How can I reapply the proper permissions, I do not want any admin to view others mail. thanks !

All Comments

  • Author
    Replies
    • #3463556

      Exchange – Able to view all users mail

      by shmaltz ·

      In reply to Exchange – Able to view all users mail

      If this Server has been upgraded from Exchange 5.5 to Exchange 2000, then it has nothing to do with the cracking (those are not hackers but crackers). Exchange 5.5 by default allowed access for admins to all mailboxes. As an admin you can gain access to any mailbox if you want. If it is only the admin that has access you should not even be worried.

    • #3462264

      Exchange – Able to view all users mail

      by colin ·

      In reply to Exchange – Able to view all users mail

      In exchange system manager drill down to the mailboxes and check the security on the mailbox / storage group. Administrators and domain admins should have a deny on the last two items. this is the default for a fresh E2K install.

    • #3458290

      Exchange – Able to view all users mail

      by tomf ·

      In reply to Exchange – Able to view all users mail

      This question was auto closed due to inactivity

Viewing 2 reply threads