Assume we have a user on our domain with an easy name (i.e. Joe) and an easy password (i.e. P@ssword123). Is it possible for a hacker to gain access to Exchange using that account (using a brute force attack) and send email as that person?
(I assume it is possible since Exchange needs to be exposed publicly over port 25 in order to receive mail.)
Is there a way to protect against this?
Our server runs Windows SBS2003 with Exchange 2003 and ISA server.