Microsoft KB Archive/899492

= A software update is available to help prevent the enumeration of Exchange Server 2003 e-mail addresses =

Article ID: 899492

Article Last Modified on 12/3/2007

-

APPLIES TO

 Microsoft Exchange Server 2003 Standard Edition Microsoft Exchange Server 2003 Enterprise Edition, when used with:  Microsoft Windows Server 2003, Datacenter Edition (32-bit x86)

 Microsoft Windows Server 2003, Standard Edition (32-bit x86)

 Microsoft Windows Server 2003, Enterprise Edition (32-bit x86) </li> Microsoft Windows Small Business Server 2003 Standard Edition</li> Microsoft Windows Small Business Server 2003 Premium Edition, when used with:  Microsoft Windows Server 2003, Datacenter Edition (32-bit x86)</li></ul>

 Microsoft Windows Server 2003, Standard Edition (32-bit x86)</li></ul>

 Microsoft Windows Server 2003, Enterprise Edition (32-bit x86)</li></ul> </li></ul>

-

<div class="notice_section">

<div class="notice_section">

Important This article contains information about how to modify the registry. Make sure to back up the registry before you modify it. Make sure that you know how to restore the registry if a problem occurs. For more information about how to back up, restore, and modify the registry, click the following article number to view the article in the Microsoft Knowledge Base:

256986 Description of the Microsoft Windows registry

<div class="summary_section">

INTRODUCTION
This article discusses a software update that you can install to help prevent the enumeration of e-mail addresses in your Microsoft Exchange Server organization. You can install this update if you run Microsoft Exchange Server 2003 on a Microsoft Windows Server 2003-based computer.

<div class="moreinformation_section">

MORE INFORMATION
Exchange Server 2003 provides a recipient filtering feature that can block an e-mail message that has been sent to a recipient that does not exist. The recipient filtering feature blocks the e-mail message by rejecting the recipient that does not exist. The recipient filtering feature blocks the e-mail message at the Simple Mail Transfer Protocol (SMTP) level. A side effect of this feature is that a malicious sender or a sender of unsolicited commercial e-mail can enumerate e-mail addresses that do exist by using a technique that is known as a directory harvest attack.

If you click to select the Filter recipients who are not in the Directory check box when you configure the recipient filtering feature, directory lookup for recipients is enabled. If directory lookup is enabled, senders of unsolicited e-mail may discover valid e-mail addresses in your Exchange Server organization.

This software update adds a feature that you can use to delay the SMTP address verification responses for each invalid address that is submitted. This feature is referred to as the tar pit feature. You can control the delay time by setting the value of the TarpitTime registry entry. By default, this feature is disabled. It takes more time and more money for an attacker to obtain the global address list by using a directory harvest attack against an SMTP server that has the tar pit feature enabled.

Note Only anonymous connections are affected by the TarpitTime registry entry. Therefore, we recommend that you enable the TarpitTime registry entry only on the Internet-facing mail gateway servers.

Software update information
A supported feature that modifies the default behavior of the product is now available from Microsoft, but it is only intended to modify the behavior that this article describes. Apply it only to systems that specifically require it. This feature may receive additional testing. Therefore, if you are not severely affected by the lack of this feature, we recommend that you wait for the next Microsoft Windows Server 2003 Service Pack that contains this feature.

To obtain this feature immediately, download the feature by following the instructions later in this article or contact Microsoft Product Support Services. For a complete list of Microsoft Product Support Services telephone numbers and information about support costs, visit the following Microsoft Web site:

http://support.microsoft.com/contactus/?ws=support

Prerequisites
You must install this software update on a Windows Server 2003-based computer.

Restart requirement
You must restart the computer after you apply this software update.

Software update replacement information
This software update does not replace any other software updates.

File information
The English version of this software update has the file attributes (or later file attributes) that are listed in the following table. The dates and times for these files are listed in Coordinated Universal Time (UTC). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time tool in Control Panel.

Windows Server 2003, 32-bit editions

<pre class="fixed_text">  Date         Time    Version       Size     File name ---   22-May-2004  00:19   6.0.3790.175  457,216  Smtpsvc.dll

Windows Server 2003, 64-bit editions

<pre class="fixed_text">  Date         Time    Version       Size       File name    Platform 21-May-2004 22:10   6.0.3790.175  1,177,088  Smtpsvc.dll  IA-64

<div class="moreinformation_section">

Configure the registry to use the tar pit feature
Warning If you use Registry Editor incorrectly, you may cause serious problems that may require you to reinstall your operating system. Microsoft cannot guarantee that you can solve problems that result from using Registry Editor incorrectly. Use Registry Editor at your own risk.

To enable the tar pit feature, you must add the TarpitTime registry entry to the registry and then configure the delay time value. To do this, follow these steps.

Note If the TarpitTime registry entry does not exist, Exchange Server behaves as if the value of this registry entry were set to 0. When the TarpitTime registry entry has a value of 0, there is no delay when the SMTP address verification responses are sent. <ol> Click Start, click Run, type regedit in the Open box, and then click OK.</li> Locate and then click the following registry subkey:

</li> On the Edit menu, point to New, and then click DWORD Value.</li> Type TarpitTime as the registry entry name, and then press ENTER.</li> On the Edit menu, click Modify.</li> Click Decimal.</li> In the Value data box, type the number of seconds that you want to delay SMTP address verification responses for each address that does not exist, and then click OK.

For example, type 5, and then click OK. This setting will delay SMTP address verification responses for 5 seconds.</li> Quit Registry Editor.</li> <li>Restart the computer.</li></ol>

<div class="references_section">