Services Partners Contact About Help Support Blog Login

Network Operations

Antivirus False Positives & Missing Messages
Posted: 10:56 am
January 11th, 2010
 
Uncategorized

Last week (January 8th and 9th) we received a dozen reports of messages that simply vanished in the ExchangeDefender system. Upon investigation it turned out that one of the antivirus engines was picking up false positives: marking messages with certain PDF attachments as infected when in fact there was no infection there. The actual infection was simply a detection of an exploit, one that can easily and inadvertently be created by older versions of Acrobat.

We have removed the antivirus engine from the rotation (don’t worry, everything is still being scanned by several other scanners). While the problem in the definition files was already addressed (Exploit.PDF-9669) and widely blogged and discussed, we need a way to deal with false positives. Prior to this we have never had an instance of a reported false positive with an antivirus engine but as more antivirus vendors get into the business of not just detecting viruses and worms but also exploits and other dangerous content, our reporting will have to get better as well.

The bigger question here is: Why was I not notified? If this happened here, it would also explain why I am never received any of the other messages. Allow me to address that in two ways:

1) Almost all of our “missing messages” tickets are related to the messages being quarantined as SPAM and not coming into LiveArchive. At the present time there is no way to get a SPAM message into LiveArchive, even after it’s released from the Quarantine. Because our replication is done at the scan time, we have to move the copying protocol elsewhere to enable post-release and SPAM content.

Followup question: But Vlad, I need to be able to view my SPAM and respond to it while my server is down!! And you can, right from admin.exchangedefender.com! All of our new enhancements are coming to that portal which is completely partner branded and next month we’ll even have training you can just point your clients to.

2) We have never before seen a false positive from an antivirus engine. We’ve seen it crash, we’ve seen it fail to detect a real infection, we’ve seen it bring the scanning node to a crawl and just about everything you’d expect from a piece of security software: just never a false reading. Consequently, we never wrote a process to monitor for the false positives and we never bothered to present the infection logs because so many contained meaningless junk. Several years ago, after countless alerts for Sober and Nimda and so on, we disabled end user reports for antivirus and it was eventually dropped from the product completely.

At this time,  we are sketching a way to put back a configurable alert system for infections should this happen again. We are also creating a system by which you’ll be able (administrators only) to access the infected quarantine items from the web UI).

IMPORTANT: While these infections appeared to be lost forever, we do have them stored on our servers. Reported messages are being released (by hand) by our support teams so if you know the message sender/recipient/subject and date the message was sent, we can retrieve the message and deliver it.

-Vlad



Huey Reboot
Posted: 10:59 am
December 11th, 2009
 
Exchange Hosting

We’ve had reports from a few partners that RPC over HTTPs is not connecting on HUEY. We are rebooting the server to rectify the issue.

Update 10:12 AM Eastern: Service has been restored and we have confirmed RPC over HTTP is functioning properly.



Livearchive Down
Posted: 9:40 am
December 9th, 2009
 
Uncategorized

We are currently working on livearchive.exchangedefender.com and the server is currently offline. The IIS application pool keeps crashing since a Windows Update from last night. We expect to have the server up shortly.

Update 9:00 AM Eastern: We’ve resolved the issue with livearchive OWA.



BES Server Maintenance
Posted: 3:23 pm
December 6th, 2009
 
Uncategorized

All of our BES servers are currently offline as we move the virtual disks to the new RAID set added in yesterday. All servers are expected to be online in the next 45 minutes.
Update 2:40 PM Eastern: The final BES server is coming online. This will complete the build and migration to the new BES host.



Livearchive Database
Posted: 1:13 pm
December 5th, 2009
 
ExchangeDefender

The livearchive database for some ExchangeDefender users is starting to show mail routing issues. We’ve disabled this database and temporarily put up a blank database. Over the weekend we will attempt to diagnose the issue with the database and remount the affected database.

Update 12-06-09: After many attempts to restore the database, the decision was made to leave the database dismounted in preparation of LiveArchive 3.0 (Due for release in Feb 2010). The current running database is >6 TB in size and direct repairs would take at least a month, leaving customers without the ability to utilize LiveArchive. All users currently have new mailboxes and we plan to migrate the >6TB database into the new LA 3.0 database.



Dewey Sharepoint Reboot
Posted: 4:58 pm
December 2nd, 2009
 
SharePoint Hosting

The sharepoint server that services users on DEWEY will be rebooted at 9PM Eastern tonight to finalize the installation of software updates. Ludwig is expected to be online no more than 10 minutes after the reboot.

Update 9:12 PM Eastern: The reboot process for LUDWIG has begun.

Update 9:25 PM Eastern The reboot has completed and LUDWIG is back online.



Backup74 Service Offline
Posted: 10:11 am
November 30th, 2009
 
Offsite Backups

The backup74 OBS service will be offline until 3pm Eastern today. During this period we will be performing upgrades to the server and moving users around to relieve resource usage on the server.

Update 1:35 PM Eastern: Service has been restored to backup74



RBL tempfails in effect across ExchangeDefender
Posted: 5:57 pm
November 23rd, 2009
 
Uncategorized

As mentioned last week, we are now deferring all mail from popular SPAM blacklists at SpamCop and SpamHaus. It is important to stress that we are not blocking or rejecting mail from these sites, merely temporarily deferring accepting messages. This subtle difference is what separates spammers from legitimate senders. Legitimate mail server operators will immediately notice they are on an RBL and will address the issue and remove themselves from it.

Our choice of SpamCop and SpamHaus came after years of use, peer reviews and our own statistical models indicating that they rarely make mistakes. We are not using third party reputation lists or greylisting which will delay mail delivery, we are just making sure that the mail arriving to you is from a legitimate source and a secure mail server.

Important Notice: tempfail effect on SureSPAM

Nearly all the messages in SureSPAM quarantine was from SpamHaus and SpamCop. As a result of us tempfailing mail from these known SPAM sources, you will see a significant decrease in SPAM and junk mail report stats as well. If you have clients that you have not yet migrated from SPAM reports to our Outlook and Desktop software, we recommend sending them the following alert:

“Today <Product Name> started temporarily deferring mail from known SPAM sources. This change will make your mail flow more efficient and reduce potentially fraudulent mail (phishing) that slips through when you whitelist large company domains.

As a result of this change you will see a significant reduction in SPAM report contents and will have less SPAM to review through the <Product Name> Outlook addin and/or Desktop agent.

P.S. Please note that we are not bouncing or rejecting mail, we are simply deferring it to allow legitimate mail server operators to address the reason why they ended up on the RBL in the first place. The two blacklists in use are SpamCop (www.spamcop.net) and SpamHaus (www.spamhaus.org) and both provide very reputable databases of known spammers. If you are having an issue receiving mail from certain recipients, have them make sure they are not on known blacklists at the above sites.”

We are closely monitoring the network during this change and will update the NOC blog if there are any issues. We do not expect anything unusual to come as a result of this implementation.



Backup74 Maintenance
Posted: 11:39 am
November 23rd, 2009
 
Offsite Backups

We will be starting maintenance on backup74 shortly. During this maintenance window we will be moving users around to new volumes on the server. Service is expected to be restored by 12:00PM Eastern.

Update 1:06 PM Eastern: The backup service has been restarted and the user move has been completed.



Server reboot HUEY
Posted: 1:07 pm
November 20th, 2009
 
Exchange Hosting

We’ve had a couple reports of users unable to connect to HUEY through RPC. We’ve restarted the IIS service but some users are still reporting issues. The HUEY server will be going offline in a couple minutes for a service reboot. The server is estimated to be down for 15 minutes during the reboot.

Update 12:04 PM Eastern: The server is now going down for the reboot.

Update 12:16 PM Eastern: The server has returned from the reboot and service has been restored.



False ExchangeDefender Notifications
Posted: 5:21 pm
November 16th, 2009
 
ExchangeDefender

We’ve received reports from a couple partners that they’ve received an email titled “your mailbox has been deactivated” that has an executable attachment that gets stripped by ExchangeDefender. This seems to be a blind attack from the outside and we’ve already implimented the checks to block these messages from coming through ExchangeDefender.

Just as a reminder, we will never email end users about issues with ExchangeDefender, we only contact our registered partner.



Liveachive reboot
Posted: 9:18 am
November 11th, 2009
 
ExchangeDefender

We are in the process of rebooting the livearchive server. Our alerting software showed periods of inaccessibility which we believe will be resolved with a reboot.

Update 8:30 AM Eastern: The livearchive server has been rebooted and is back online. Services are running 100%.



Daisy SSL Renewal
Posted: 11:32 pm
November 10th, 2009
 
Exchange Hosting

We are about to replace the SSL certificate on our 2003 server Daisy. During the replacement RPC over HTTPs  may be unavailable but will be restored shortly.

Update 10:39 PM Eastern: The SSL has been replaced on Daisy and service has been restored 100%.



ExchangeDefender Outbound New IP Adresses
Posted: 12:22 pm
November 10th, 2009
 
Announcements, ExchangeDefender

In preparation for the release of ExchangeDefender 5.0 we’ve installed 4 new servers to process outbound mail for ExchangeDefender clients.

This transition was seamless and shouldn’t require any work from our partners, however any clients who are using SPF records will need to add the following IP addresses

p4:65.99.255.234
ip4:65.99.255.237
ip4:65.99.255.238
ip4:65.99.255.239



Stress test HUEY
Posted: 7:10 pm
October 18th, 2009
 
Exchange Hosting

At 7:10 PM Eastern we will begin stress test maintenance on HUEY that is scheduled to last until 10PM Eastern. We are performing click tests and harddrive upgrades. There will be periods of inaccessibility through OWA and Outlook.

Update 2:07 AM: Maintenance has completed and the database has been moved to the new drive. Service has been restored 100%.

Update 937 PM: The hard drives are in place however the copy is taking longer than expected. New mail is being queued so there will be no lost emails during this maintenance.



Australia Exchange
Posted: 11:02 pm
October 14th, 2009
 
Exchange Hosting

The Australian exchange server is currently offline for network upgrades from 00:00 – 04:00 GMT +10

Due to increased network activity over the past several month in the data center, Servers Australia technicians will be replacing several Fast Ethernet Interfaces with Gigabit Ethernet and Multimode Fiber interfaces in the Sydney Core Routers.

The maintaince upgrades of our entire data center network within Equinix Mascot and the SAU Data Center at Tuggerah is to provide a more reliable and responsive experience.



Service Maintenance on HUEY
Posted: 8:20 pm
October 8th, 2009
 
Exchange Hosting

We have received a few complaints about outlook not updating on HUEY. We will be restarting the services momentarily and if a reboot is required, this post will be updated.



Backup74 Update
Posted: 10:21 am
September 29th, 2009
 
Offsite Backups

At 10:30 AM Eastern we will be shutting off the Ahsay OBS service on Backup74 to install the latest updates to the OBS platform. Service is expected to be down for less than 15 minutes.

Update 10:35 AM Eastern: The update has been completed. Service has been restored to Backup74.

Update 10:31 AM Eastern: The service has been shut off for the update.



Backup74
Posted: 9:15 am
September 28th, 2009
 
Offsite Backups

Over the weekend, the Tomcat web service on backup74 stopped answering new requests. We’ve opened up a ticket with Ahsay and was provided with a hotfix to install. We are going to try to make the changes to the Tomcat config files to restore service before installing the hotfix patch. Service is expected to be functional within the hour.

Update 10:50pm Eastern: Service to backup74 has been restored without installing the hotfix. We are planning to install a stable patch upgrade to the server later in the week.



Backup74
Posted: 1:18 pm
September 25th, 2009
 
Offsite Backups

The Ahsay OBS service has been stopped on Backup74 while we move users around on the volumes.



Own Web Now Blog

Own Web Now Corp Network Operations Center is designed specifically to alert and inform you of routine and emergency maintenance tasks being conducted on our network. Every large product group is represented in the feeds below and we urge you to follow the global alert feed or at least the individual service feeds to which you subscribe.


News & Events

The best way to stay in touch with us is through our blog, but from time to time we do special things that we feel you might find interesting. Check them out!


OWN SPAM Show 15
Big in 2010, Karl, Erick and Vlad talk about 2009 and what they predict will contribute in a big way to IT business in 2010.

Alternative content




OWN SPAM Show 14
Managing your "humans" and turning them into resources with Karl, Vlad and special guest: Monique Rogers from CharTec.net. Learn how to successfully find, hire and motivate employees.

Alternative content