HEy EVeryone,
I am having another issue with a client running SBS Server 2000 with Exchange 2000. The SMTP connector is sending out spam like crazy, and I cant find where it is coming from! I figured it was a reverse NDR attack, but I have turned off NDR's a month ago. I have tested the Port 25 to make sure it is not an open relay, which it is not. I have ran every Anti Virus solution out there. Anyideas where this is coming from? Here is a bit of the SMTP logging that I have captured.
++++++++++++++++++++++++++
++++++++++
++++++++++
++++++++++
++++++++++
++++++++++
+++++++++
004-10-22 17:37:50 65.248.18.232 OutboundConnectionResponse
SMTPSVC1 CAELWYN01 - 25 - 0 0 45 0 79 SMTP - - - -
2004-10-22 17:37:50 65.248.18.232 OutboundConnectionCommand SMTPSVC1 CAELWYN01 - 25 EHLO 0 0 4 0 125 SMTP - - - -
2004-10-22 17:37:50 65.248.18.232 OutboundConnectionResponse
SMTPSVC1 CAELWYN01 - 25 - 0 0 20 0 219 SMTP - - - -
2004-10-22 17:37:50 65.248.18.232 OutboundConnectionCommand SMTPSVC1 CAELWYN01 - 25 MAIL 0 0 4 0 219 SMTP - - - -
2004-10-22 17:37:50 65.248.18.232 OutboundConnectionResponse
SMTPSVC1 CAELWYN01 - 25 - 0 0 6 0 297 SMTP - - - -
2004-10-22 17:37:50 65.248.18.232 OutboundConnectionCommand SMTPSVC1 CAELWYN01 - 25 RCPT 0 0 4 0 297 SMTP - - - -
2004-10-22 17:37:51 65.248.18.232 OutboundConnectionResponse
SMTPSVC1 CAELWYN01 - 25 - 0 0 99 0 1485 SMTP - - - -
2004-10-22 17:37:51 65.248.18.232 OutboundConnectionCommand SMTPSVC1 CAELWYN01 - 25 RSET 0 0 4 0 1485 SMTP - - - -
2004-10-22 17:37:51 65.248.18.232 OutboundConnectionResponse
SMTPSVC1 CAELWYN01 - 25 - 0 0 6 0 1579 SMTP - - - -
2004-10-22 17:37:51 65.248.18.232 OutboundConnectionCommand SMTPSVC1 CAELWYN01 - 25 QUIT 0 0 4 0 1579 SMTP - - - -
2004-10-22 17:37:51 65.248.18.232 OutboundConnectionResponse
SMTPSVC1 CAELWYN01 - 25 - 0 0 7 0 1657 SMTP - -
++++++++++++++++++++++++++
++++++++++
++++++++++
++++++++++
++++++++++
++++++++++
++++++++++
Any ideas on what this may be??? I am not sure how to decipher the SMTP logs! TIA...Chris