{"id":314,"date":"2022-01-31T22:17:00","date_gmt":"2022-01-31T09:17:00","guid":{"rendered":"https:\/\/www.howdoiuseacomputer.com\/?p=314"},"modified":"2022-02-01T00:22:54","modified_gmt":"2022-01-31T11:22:54","slug":"is-your-hybrid-exchange-server-safe-or-unknowingly-exposed","status":"publish","type":"post","link":"https:\/\/www.howdoiuseacomputer.com\/index.php\/2022\/01\/31\/is-your-hybrid-exchange-server-safe-or-unknowingly-exposed\/","title":{"rendered":"Is your Hybrid Exchange Server SAFE or unknowingly EXPOSED?"},"content":{"rendered":"\n<p>Hello and happy 2022! &#x1f973; I hope the year has started off as well as it possibly can for you (aside from the holiday ending a bit too early of course!)&#8230; &#x1f37a;&#x1f62d; &#8230;right back to work!<br><\/p>\n\n\n\n<p><strong>Now, is your Exchange environment safe!!??<\/strong>  <strong>Really?  Is it?<\/strong><\/p>\n\n\n\n<p>I love this utility called \u2018SMTP Diag Tool\u2019. It\u2019s great for seeing whether you can connect directly to port 25 of an Exchange server. In most cases, if you can, you can send unauthenticated email to accepted domains within the organisation, because that&#8217;s how email used to work right?<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"521\" height=\"584\" src=\"https:\/\/www.howdoiuseacomputer.com\/wp-content\/uploads\/2022\/01\/image.png\" alt=\"\" class=\"wp-image-318\" srcset=\"https:\/\/www.howdoiuseacomputer.com\/wp-content\/uploads\/2022\/01\/image.png 521w, https:\/\/www.howdoiuseacomputer.com\/wp-content\/uploads\/2022\/01\/image-268x300.png 268w\" sizes=\"(max-width: 521px) 100vw, 521px\" \/><figcaption>SMTP Diag Tool<\/figcaption><\/figure>\n\n\n\n<p>Before we had a mail filtering service in front of Exchange, email was sent directly between servers (in fact if Exchange was configured to use SpamHaus and SpamCop lookups, it did a pretty good job itself!).  But I digress&#8230;<\/p>\n\n\n\n<p>In many cases lately I have found I can connect directly to, and send unchecked email to Exchange servers, most often using &#8216;mail&#8217; or &#8216;webmail&#8217; hostnames.  This method bypasses MX records, mail filtering services and also tells you probably have port 443 wide open as well.  Clients are shocked &#8211; bypassing my mail filter &#8211; really?  Yep!  Here are the scenarios:<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li><strong>You have a mail filtering service<\/strong>, but nobody set up the firewall or Exchange rules to restrict inbound email to the services sending IP Addresses (applies to on-premises and 365).<\/li><li><strong>You have a Hybrid Exchange configuration<\/strong>, some or all mailboxes are in the cloud but you still have port 25 and 443 open to your on-premises server.<\/li><li><strong>And a less serious case but a definite gap to plug <\/strong>&#8211; you are cloud only or hybrid, but have not configured rules to stop other tenants from emailing you directly (this would need to be a targeted attack, but I&#8217;m sure the attackers will automate the creation of that attack in future if not already).<\/li><\/ol>\n\n\n\n<p><strong>To fix this<\/strong> there are several options; the more configured the better!<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li><strong>The best step to take is restricting incoming traffic at the firewall.  <\/strong>If you can&#8217;t use &#8216;Internet databases&#8217; as firewall objects, throw away your firewall and get a suitable FortiGate model.  <\/li><li><strong>Use the &#8216;Microsoft-Azure&#8217; and &#8216;Microsoft-Outlook&#8217; objects <\/strong>to restrict incoming (and outbound if you can) 25 traffic to Microsoft&#8217;s servers (if you are hybrid and using Defender mail filtering) <strong>OR<\/strong> by restricting to your mail filtering service&#8217;s IP range for port 25 (if you are on-premises, or routing through it).<\/li><li><strong>Use the Exchange Hybrid Agent! <\/strong>Re-run the wizard and choose the Agent option (you may need to install it manually first if running 2010). This allows you to <strong>close port 443 inbound entirely,<\/strong> by performing free \/ busy lookups and mailbox moves through an Azure App Proxy.<\/li><li><strong>For port 443<\/strong>, you can also use an<strong> Azure Application Proxy<\/strong> to act as a gateway to your environment if you are not Hybrid and it must be contactable from the internet (<strong>IMO Everyone <\/strong>should be using this for internet facing services &#8211; then you can close all inbound ports on your firewall and let Microsoft do the work!! (security team = &#x2705;)<\/li><li>If you do have inbound 443, use IIS with the <strong>URL Rewrite <\/strong>module to block access to any virtual directories that are not required (you&#8217;re not still using ActiveSync I hope!!?).  <\/li><li><strong>You can also <\/strong>modify the <strong>Default Receive Connector <\/strong>in Exchange only to accept from a filtering service, or 365, but this is harder to maintain and shouldn&#8217;t be needed if the firewall is configured correctly.<\/li><li><strong>For the cloud-only and Hybrid scenarios<\/strong>, make sure you have implemented the Exchange rules to ensure only mail using your MX record will be delivered, ensuring it traverses the Mail Filtering protection of Exchange Online: <a href=\"https:\/\/techcommunity.microsoft.com\/t5\/exchange-team-blog\/advanced-office-365-routing-locking-down-exchange-on-premises\/ba-p\/609238\">Advanced Office 365 Routing: Locking Down Exchange On-Premises when MX points to Office 365 &#8211; Microsoft Tech Community<\/a>.<\/li><\/ol>\n\n\n\n<p><strong>I also recommend <\/strong>performing the following tasks to ensure maximum security for your environment, first focusing on Hybrid Exchange seeing as that is the most common scenario.<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>AD Connect<\/strong> &#8211; if it&#8217;s been around for a while, make sure it is now on a 2016\/2019 server with TLS 1.2 enabled.  You must have these OS to install the latest version.  Also make sure it is configured for Hybrid Exchange while you are there.<\/li><\/ul>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Hopefully you are on Exchange 2016<\/strong> (since that is free for Hybrid and 2019 is not), if not plan and get it done ASAP.  Don&#8217;t use 2 vCPU and 8GB memory for your Exchange Hybrid server, what are we, skinflints? 4 vCPU and 16GB are recommended and should be easily achievable in any environment.  If not then I cry for you&#8230; &#x1f62d;&#x1f62d;<\/li><\/ul>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Use Azure Automation <\/strong>with <strong>Server Update Management <\/strong>to automatically patch your on-premises servers, even if you don&#8217;t have Azure yet this is worth enabling it for&#8230; WSUS &#8211; Yuuuuk! &#x1f92e;&#x1f92e;<\/li><\/ul>\n\n\n\n<p>Until next time &#8211; chur chur from Simon!<\/p>\n<div class=\"pvc_clear\"><\/div><p id=\"pvc_stats_314\" class=\"pvc_stats all  \" data-element-id=\"314\" style=\"\"><i class=\"pvc-stats-icon small\" aria-hidden=\"true\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.0\" viewBox=\"0 0 502 315\" preserveAspectRatio=\"xMidYMid meet\"><g transform=\"translate(0,332) scale(0.1,-0.1)\" fill=\"\" stroke=\"none\"><path d=\"M2394 3279 l-29 -30 -3 -207 c-2 -182 0 -211 15 -242 39 -76 157 -76 196 0 15 31 17 60 15 243 l-3 209 -33 29 c-26 23 -41 29 -80 29 -41 0 -53 -5 -78 -31z\"\/><path d=\"M3085 3251 c-45 -19 -58 -50 -96 -229 -47 -217 -49 -260 -13 -295 52 -53 146 -42 177 20 16 31 87 366 87 410 0 70 -86 122 -155 94z\"\/><path d=\"M1751 3234 c-13 -9 -29 -31 -37 -50 -12 -29 -10 -49 21 -204 19 -94 39 -189 45 -210 14 -50 54 -80 110 -80 34 0 48 6 76 34 21 21 34 44 34 59 0 14 -18 113 -40 219 -37 178 -43 195 -70 221 -36 32 -101 37 -139 11z\"\/><path d=\"M1163 3073 c-36 -7 -73 -59 -73 -102 0 -56 133 -378 171 -413 34 -32 83 -37 129 -13 70 36 67 87 -16 290 -86 209 -89 214 -129 231 -35 14 -42 15 -82 7z\"\/><path d=\"M3689 3066 c-15 -9 -33 -30 -42 -48 -48 -103 -147 -355 -147 -375 0 -98 131 -148 192 -74 13 15 57 108 97 206 80 196 84 226 37 273 -30 30 -99 39 -137 18z\"\/><path d=\"M583 2784 c-38 -19 -67 -74 -58 -113 9 -42 211 -354 242 -373 16 -10 45 -18 66 -18 51 0 107 52 107 100 0 39 -1 41 -124 234 -80 126 -108 162 -133 173 -41 17 -61 16 -100 -3z\"\/><path d=\"M4250 2784 c-14 -9 -74 -91 -133 -183 -95 -150 -107 -173 -107 -213 0 -55 33 -94 87 -104 67 -13 90 8 211 198 130 202 137 225 78 284 -27 27 -42 34 -72 34 -22 0 -50 -8 -64 -16z\"\/><path d=\"M2275 2693 c-553 -48 -1095 -270 -1585 -649 -135 -104 -459 -423 -483 -476 -23 -49 -22 -139 2 -186 73 -142 361 -457 571 -626 285 -228 642 -407 990 -497 242 -63 336 -73 660 -74 310 0 370 5 595 52 535 111 1045 392 1455 803 122 121 250 273 275 326 19 41 19 137 0 174 -41 79 -309 363 -465 492 -447 370 -946 591 -1479 653 -113 14 -422 18 -536 8z m395 -428 c171 -34 330 -124 456 -258 112 -119 167 -219 211 -378 27 -96 24 -300 -5 -401 -72 -255 -236 -447 -474 -557 -132 -62 -201 -76 -368 -76 -167 0 -236 14 -368 76 -213 98 -373 271 -451 485 -162 444 86 934 547 1084 153 49 292 57 452 25z m909 -232 c222 -123 408 -262 593 -441 76 -74 138 -139 138 -144 0 -16 -233 -242 -330 -319 -155 -123 -309 -223 -461 -299 l-81 -41 32 46 c18 26 49 83 70 128 143 306 141 649 -6 957 -25 52 -61 116 -79 142 l-34 47 45 -20 c26 -10 76 -36 113 -56z m-2057 25 c-40 -58 -105 -190 -130 -263 -110 -324 -59 -707 132 -981 25 -35 42 -64 37 -64 -19 0 -241 119 -326 174 -188 122 -406 314 -532 468 l-58 71 108 103 c185 178 428 349 672 473 66 33 121 60 123 61 2 0 -10 -19 -26 -42z\"\/><path d=\"M2375 1950 c-198 -44 -350 -190 -395 -379 -18 -76 -8 -221 19 -290 114 -284 457 -406 731 -260 98 52 188 154 231 260 27 69 37 214 19 290 -38 163 -166 304 -326 360 -67 23 -215 33 -279 19z\"\/><\/g><\/svg><\/i> <img loading=\"lazy\" decoding=\"async\" width=\"16\" height=\"16\" alt=\"Loading\" src=\"https:\/\/www.howdoiuseacomputer.com\/wp-content\/plugins\/page-views-count\/ajax-loader-2x.gif\" border=0 \/><\/p><div class=\"pvc_clear\"><\/div>","protected":false},"excerpt":{"rendered":"<p>Hello and happy 2022! &#x1f973; I hope the year has started off as well as it possibly can for you (aside from the holiday ending a bit too early of course!)&#8230; &#x1f37a;&#x1f62d; &#8230;right back to work! Now, is your Exchange environment safe!!?? Really? Is it? I love this utility called \u2018SMTP Diag Tool\u2019. It\u2019s great [&hellip;]<\/p>\n<div class=\"pvc_clear\"><\/div>\n<p id=\"pvc_stats_314\" class=\"pvc_stats all  \" data-element-id=\"314\" style=\"\"><i class=\"pvc-stats-icon small\" aria-hidden=\"true\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.0\" viewBox=\"0 0 502 315\" preserveAspectRatio=\"xMidYMid meet\"><g transform=\"translate(0,332) scale(0.1,-0.1)\" fill=\"\" stroke=\"none\"><path d=\"M2394 3279 l-29 -30 -3 -207 c-2 -182 0 -211 15 -242 39 -76 157 -76 196 0 15 31 17 60 15 243 l-3 209 -33 29 c-26 23 -41 29 -80 29 -41 0 -53 -5 -78 -31z\"\/><path d=\"M3085 3251 c-45 -19 -58 -50 -96 -229 -47 -217 -49 -260 -13 -295 52 -53 146 -42 177 20 16 31 87 366 87 410 0 70 -86 122 -155 94z\"\/><path d=\"M1751 3234 c-13 -9 -29 -31 -37 -50 -12 -29 -10 -49 21 -204 19 -94 39 -189 45 -210 14 -50 54 -80 110 -80 34 0 48 6 76 34 21 21 34 44 34 59 0 14 -18 113 -40 219 -37 178 -43 195 -70 221 -36 32 -101 37 -139 11z\"\/><path d=\"M1163 3073 c-36 -7 -73 -59 -73 -102 0 -56 133 -378 171 -413 34 -32 83 -37 129 -13 70 36 67 87 -16 290 -86 209 -89 214 -129 231 -35 14 -42 15 -82 7z\"\/><path d=\"M3689 3066 c-15 -9 -33 -30 -42 -48 -48 -103 -147 -355 -147 -375 0 -98 131 -148 192 -74 13 15 57 108 97 206 80 196 84 226 37 273 -30 30 -99 39 -137 18z\"\/><path d=\"M583 2784 c-38 -19 -67 -74 -58 -113 9 -42 211 -354 242 -373 16 -10 45 -18 66 -18 51 0 107 52 107 100 0 39 -1 41 -124 234 -80 126 -108 162 -133 173 -41 17 -61 16 -100 -3z\"\/><path d=\"M4250 2784 c-14 -9 -74 -91 -133 -183 -95 -150 -107 -173 -107 -213 0 -55 33 -94 87 -104 67 -13 90 8 211 198 130 202 137 225 78 284 -27 27 -42 34 -72 34 -22 0 -50 -8 -64 -16z\"\/><path d=\"M2275 2693 c-553 -48 -1095 -270 -1585 -649 -135 -104 -459 -423 -483 -476 -23 -49 -22 -139 2 -186 73 -142 361 -457 571 -626 285 -228 642 -407 990 -497 242 -63 336 -73 660 -74 310 0 370 5 595 52 535 111 1045 392 1455 803 122 121 250 273 275 326 19 41 19 137 0 174 -41 79 -309 363 -465 492 -447 370 -946 591 -1479 653 -113 14 -422 18 -536 8z m395 -428 c171 -34 330 -124 456 -258 112 -119 167 -219 211 -378 27 -96 24 -300 -5 -401 -72 -255 -236 -447 -474 -557 -132 -62 -201 -76 -368 -76 -167 0 -236 14 -368 76 -213 98 -373 271 -451 485 -162 444 86 934 547 1084 153 49 292 57 452 25z m909 -232 c222 -123 408 -262 593 -441 76 -74 138 -139 138 -144 0 -16 -233 -242 -330 -319 -155 -123 -309 -223 -461 -299 l-81 -41 32 46 c18 26 49 83 70 128 143 306 141 649 -6 957 -25 52 -61 116 -79 142 l-34 47 45 -20 c26 -10 76 -36 113 -56z m-2057 25 c-40 -58 -105 -190 -130 -263 -110 -324 -59 -707 132 -981 25 -35 42 -64 37 -64 -19 0 -241 119 -326 174 -188 122 -406 314 -532 468 l-58 71 108 103 c185 178 428 349 672 473 66 33 121 60 123 61 2 0 -10 -19 -26 -42z\"\/><path d=\"M2375 1950 c-198 -44 -350 -190 -395 -379 -18 -76 -8 -221 19 -290 114 -284 457 -406 731 -260 98 52 188 154 231 260 27 69 37 214 19 290 -38 163 -166 304 -326 360 -67 23 -215 33 -279 19z\"\/><\/g><\/svg><\/i> <img loading=\"lazy\" decoding=\"async\" width=\"16\" height=\"16\" alt=\"Loading\" src=\"https:\/\/www.howdoiuseacomputer.com\/wp-content\/plugins\/page-views-count\/ajax-loader-2x.gif\" border=0 \/><\/p>\n<div class=\"pvc_clear\"><\/div>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[9],"tags":[43,24,54,25,51,52,55,50,47,48,39,53,49],"class_list":["post-314","post","type-post","status-publish","format-standard","hentry","category-ramblings","tag-ad-connect","tag-exchange","tag-exchange-hybrid","tag-exchange-online","tag-firewall","tag-fortigate","tag-mail-filtering","tag-mail-flow","tag-port-25","tag-port-443","tag-security","tag-smtp-diag-tool","tag-virtual-directory"],"post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/www.howdoiuseacomputer.com\/index.php\/wp-json\/wp\/v2\/posts\/314"}],"collection":[{"href":"https:\/\/www.howdoiuseacomputer.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.howdoiuseacomputer.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.howdoiuseacomputer.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.howdoiuseacomputer.com\/index.php\/wp-json\/wp\/v2\/comments?post=314"}],"version-history":[{"count":4,"href":"https:\/\/www.howdoiuseacomputer.com\/index.php\/wp-json\/wp\/v2\/posts\/314\/revisions"}],"predecessor-version":[{"id":320,"href":"https:\/\/www.howdoiuseacomputer.com\/index.php\/wp-json\/wp\/v2\/posts\/314\/revisions\/320"}],"wp:attachment":[{"href":"https:\/\/www.howdoiuseacomputer.com\/index.php\/wp-json\/wp\/v2\/media?parent=314"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.howdoiuseacomputer.com\/index.php\/wp-json\/wp\/v2\/categories?post=314"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.howdoiuseacomputer.com\/index.php\/wp-json\/wp\/v2\/tags?post=314"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}