Hi,
It appears that we are being used to send spam. Our domino server has started sending hundreds of messages to other users. I am not at the offfice so I can not put a sniffer on the wire, but I am having trouble finding where the mail is originating from. I would have expected to see an internal ip address of one of our clients if the infection was there. Anyone have any ideas on how to troubleshoot this?
Our basic setup is this
Notes Client
DAMO Client
Use Domino to send SMTP mail to our LINUX sendmail server (Outbound)
Messages have spoofed from/to addresses and are foreign (Russia, Taiwan,UK)
Thanks for any help you can provide.
Here is a sample from the Notes Log
02/24/2008 02:36:16 PM SMTP Server: Message 006BB0B4 (MessageID: <OATFYRCZSFGBRYOHBDXJKPD@m
s69.hinet.
net>) received
02/24/2008 02:36:16 PM Router: Transferring mail to domain POBOX.RITE.COM (host POBOX.RITE.COM [192.168.0.3]) via SMTP
02/24/2008 02:36:16 PM SMTP Server: 219-84-10-36-adsl-tpe.dyna
mic.so-net
.net.tw (219.84.10.36) disconnected. 1 message[s] received
02/24/2008 02:36:20 PM SMTP Server: Message 006BB28D (MessageID: <ZYPVYXLGXWGUQVUVJDPKDD@ms
15.hinet.n
et>) received
02/24/2008 02:36:21 PM SMTP Server: 219-84-10-250-adsl-tpe.dyn
amic.so-ne
t.net.tw (219.84.10.250) disconnected. 1 message[s] received
02/24/2008 02:36:32 PM SMTP Server: 219-84-10-49-adsl-tpe.dyna
mic.so-net
.net.tw (219.84.10.49) connected
02/24/2008 02:36:36 PM SMTP Server: Message 006BB8B0 (MessageID: <JGCPZPUVOLFBIEJZPJVZUBUGQ
@ms4.hinet
.net>) received
02/24/2008 02:36:36 PM SMTP Server: 219-84-10-49-adsl-tpe.dyna
mic.so-net
.net.tw (219.84.10.49) disconnected. 1 message[s] received
02/24/2008 02:36:37 PM Router: Transferring mail to domain POBOX.RITE.COM (host POBOX.RITE.COM [192.168.0.3]) via SMTP
02/24/2008 02:36:38 PM Router: Transferred 1 messages to POBOX.RITE.COM (host POBOX.RITE.COM) via SMTP
02/24/2008 02:36:39 PM Router: Transferred 2 messages to POBOX.RITE.COM (host POBOX.RITE.COM) via SMTP
02/24/2008 02:36:42 PM Router: Message 006BB0B4 transferred to POBOX.RITE.COM for a0910tinasusan@yahoo.com.t
w via SMTP
02/24/2008 02:36:42 PM Router: Message 006BB0B4 transferred to POBOX.RITE.COM for ecnvv@msa.hinet.net via SMTP
ETC ETC ETC
Start Free Trial