Microsoft: For better security, scan more Exchange server objects
- Reference: 1677402010
- News link: https://www.theregister.co.uk/2023/02/26/microsoft_exchange_server_exclusion/
- Source link:
In particular, the software giant said this week that sysadmins should now include the Temporary ASP.NET files, Inetsrv folders, and the PowerShell and w3wp processes on the list of files and folders to be run through antivirus systems.
Scanning these objects will help fend off such threats as IIS webshells and backdoor modules, said the vendor.
[1]
"Times have changed, and so has the cybersecurity landscape," Microsoft's Exchange Team wrote in a [2]post this week. "We've found that some existing exclusions … are no longer needed."
[3]
[4]
That likely will come as good news to many Exchange server users, now that the systems are becoming an increasingly popular target of cybercriminals given the large amount of critical data housed on the systems. That includes corporate mailboxes to address books, which can hold such information as employee titles and contact information and organizational structures, all of which can be useful in phishing and similar attacks.
Exchange also has data involving permissions in Active Directory and access to cloud environments connected to the enterprise.
[5]
Microsoft late last month [6]urged Exchange server users to make sure their systems are up-to-date with the latest Cumulative and Security updates and hardened against cyberattacks. The company warned that miscreants are always searching Shodan and other sources for unpatched Enterprise servers to exploit.
Redmond in November 2022 [7]fixed two ProxyNotShell flaws, one of which was a remote code execution (RCE) bug and the other a server-side request forgery flaw. In March 2021, the company released out-of-band patches for four zero-day vulnerabilities being exploited, including [8]ProxyLogon that had been widely abused by a dozen or so cybercrime gangs – including Hafnium – during the previous two months.
Removing the latest objects from the exclusion list will further increase Exchange server security, according to the Exchange Team.
[9]
There are still a lot of items on the Exchange server exclusion list. A key reason an object is put on it is that having them scanned by the antivirus system could cause performance problems, errors, or crashes.
"The biggest potential problem is a Windows antivirus program might lock or quarantine an open log file or database file that Exchange needs to modify," Microsoft wrote in another [10]post this week. "This can cause severe failures in Exchange Server, and it might also generate 1018 event log errors. Therefore, excluding these files from being scanned by the Windows antivirus program is very important."
In addition, Windows antivirus programs can't replace email-based anti-spam and anti-malware tools, the company wrote. Windows antivirus programs running on Windows servers can't detect such threats as viruses, malware, and spam that are distributed only via email.
[11]Microsoft to enterprises: Patch your Exchange servers
[12]FBI smokes ransomware Hive after secretly buzzing around gang's network for months
[13]First Patch Tuesday of the year explodes with in-the-wild exploit fix
[14]Notorious Emotet botnet returns after a few months off
That said, the Exchange Team wrote that removing the aforementioned files and processes from the exclusion list won't affect the stability or performance of the server when using Microsoft Defender on Exchange Server 2019 and running the latest Exchange server updates.
In addition, exclusions can also be removed from systems running Exchange Server 2016 and 2013 (which will hit [15]end-of-support in April). When running the antivirus scan on those systems with the exclusions removed, if problems arise, sysadmins should put the exclusions back in place and report the issues to Microsoft, the company said. ®
Get our [16]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y-s705uUBKRVigTypASUCQAAAIg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://techcommunity.microsoft.com/t5/exchange-team-blog/update-on-the-exchange-server-antivirus-exclusions/ba-p/3751464
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y-s705uUBKRVigTypASUCQAAAIg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y-s705uUBKRVigTypASUCQAAAIg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y-s705uUBKRVigTypASUCQAAAIg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2023/01/28/microsoft_patch_exchange_servers/
[7] https://www.theregister.com/2022/11/09/microsoft_november_2022_patch_tuesday/
[8] https://www.theregister.com/2021/03/12/github_disappears_exploit/
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y-s705uUBKRVigTypASUCQAAAIg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[10] https://learn.microsoft.com/en-us/exchange/antispam-and-antimalware/windows-antivirus-software?view=exchserver-2019
[11] https://www.theregister.com/2023/01/28/microsoft_patch_exchange_servers/
[12] https://www.theregister.com/2023/01/26/fbi_hive_ransomware/
[13] https://www.theregister.com/2023/01/11/patch_tuesday_january_2023/
[14] https://www.theregister.com/2022/11/17/emotet_botnet_returns/
[15] https://techcommunity.microsoft.com/t5/exchange-team-blog/exchange-server-2013-end-of-support-approaching-fast/ba-p/3741491
[16] https://whitepapers.theregister.com/
You are using Clang... that is the problem. You should be using the VS* stuff that they try to shove through your throat all the time.
Just like they annoy users who want another browser than edge, they insist on making it difficult to move outside the "garden".
Why not remove the root cause?
A proper virus scanner should mark the whole of Exchange as a virus and recommend deletion. It's been a security problem from the day it was introduced and, like all other Microsoft products, has only become more complicated but not more secure.
Once you open your mind to the fact that there are actually other Operating Systems out there you will discover there are more products that do the job, but with far less risk. Given that the threat of malware and breaches is ever increasing, it may be worth starting to look for other options.
I'm amused that Defender still insists on rescanning the identical, unchanged data multiple times a second during compilation.
Clang hasn't changed in the previous 10 milliseconds, don't check it again.
Ah, no, the word is "annoyed". Yes, that's right.