The other day I wrote an article on why you should consider limiting the session concurrency to RFC established standards if you don’t have decent perimeter security. Your really should get something, but there is quite a bit you can do yourself to help deal with mailbombs.
Mailbombs, you say? Yes, mailbombs. Kind of like how you spec’ed that server for 10 employees and never considered it would have to one day deal with 10,000 messages an hour? Well, it’s happening. The more systems get owned, the more computers get compromised, the larger the broadcast storms become. And yes, you get to hear it first because I run one of the largest mail networks in the world, but don’t think for a minute that these threats aren’t coming down to you. Over the past week I have been hearing from one partner after another that has his or hers appliance on its knees. Why? The volume is explosive.
And even without perimeter security, there is something you can do with Exchange 2003 alone. Let’s look at some Default bafoonery:

Yes, those are Exchange 2003 default settings. The two of particular interest are the limits for the number of messages per connection and number of recipients per message. You can just look at those limits for a second and note their absurdity – 64000 recipients per message?

Another area of interest is the checkbox next to “Perform reverse DNS lookup on incoming messages” – some folks had a bright idea to use this as an antispam measure. Please do not. If you’re being mailbombed the last thing you want to do is reduce your mail flow to a crawl while you run a DNS query for each incoming connection.
Finally, the least likely option to appeal to you: disable IMF. IMF bayesian (SmartScreen) technology is very expensive when it comes to resources and can easilly exhaust your systems resources during the high load averages – so turn it off and let the workstations deal with the issue. Unless you are rejecting fairly low scores, having IMF around during mailbombs will not help you. Don’t think IMF is killing your box? Get some stats:

You can get performance counters. Two of particularly interesting ones are “MSExchange Intelligent Message Filter \ Total Messages Scanned for UCE” and “MSExchangeMTA Connections \ Inbound Messages Total” which given a little bit of time and resources will show you when you are experiencing spikes and whether you’re truely experiencing a problem to begin with.
Obviously, it is fairly difficult to tell if you have an anomaly if you don’t know what your baseline (“known standard metric” or “business as usual”) numbers are so its important to actually manage your servers. Those tasks, and the above settings and defaults explained in detail is of course a subject for a lengthy article…. but if you’re getting swamped right now this ought to help you out just a little bit while you weather the storm.


I feel awesome, however: Here there be truths to which thee might not find comfort in. I’ve said last year and I will say it again:
What it really boils down to is a loose network of casual acquaintances (if you’re lucky, “friends”) who from time to time share items of common knowledge and keep every bit of competitive insight deep inside their pockets. It is a collection of at-best defunct IT shop owners who figured their only way to salvation is not by doing IT but by telling others how to do it. It is a pile of forums where a group of largely defeated people gets an outlet to moan about their troubles, provoke a response and still get a feeling of belonging, as if someone still cares about them. At its best and finest, it is a collection of defunct technicians stabbing in the dark for a business plan that promises not to be a failure, unlike everything else they have tried so far. There isn’t a whole lot of success, but there is a lot of hope…..
And, in the crowning confirmation of all of the above, a flourescently fairy will get in front of the audience that paid $500 a ticket to hear shit it ought to know already and proclaim: “SBS community isn’t dead, it’s bigger than its ever been before!” now go pay my vendors!
P.S. This is my last and final post about the supposed SBS community. Last night a little birdie forwarded me a pst of the discussion threads from a group I abandoned a long time ago as an irrelevant pursuit of the inevitable: that aside from maybe two dozen charismatic and energetic IT people with really good hearts and the willingness to teach it is just a fruitless enterprise of people trying to sell their stuff to one another or stand in the way of any bit of progress as a moral obstacle. Everything else just proves to be a marginal success until the main person realizes their efforts go to waste and they finally move on. The only thing left over is the bunch “despite all my rage I’m just an SBSer in a cage” that hasn’t realized all of this yet. Comments closed as it simply doesn’t matter what you think, it only matters that you accept it and find a positive way to continue instead of banging your head against the wall about why the community isn’t working the way you think it ought to.