We help IT Professionals succeed at work.

how did a spam email generated and sent from my server?

cuc888
cuc888 asked
on
411 Views
Last Modified: 2011-09-20
my server is windows 2003 with exchange 2003. last couple days, number of accounts has sent out mails like these below samples. i can't figure out how it happen or if my server is infected or local user machines are infected with viruses. the email was sent out using authorized account and sent to the same account under alias address as below. different subject and body content were sent out each time.

From: Jeanine [mailto:firname_lastname@domainname.com]
Sent: Wednesday, June 14, 2006 1:55 PM
To: firstname lastname
Subject: RE: yOur pi11z r3quest
Importance: High

HOw are yOu Guys?!

Please open your mind for a simple thing
Internet provided products always cheaper than others.
You may agree or not, but this is a fact
Just compare the numbers and get the same goods for a half value
You may agree or not, but this is a fact

0HNiTsfUebnAZb9XR4DM
Comment
Watch Question

Commented:
Enable message tracking on your server properties in ESM.  Query on the next message you receive.  This is to make sure the messages were not just spooked emails (crafted to look like they came from your server).

You might also check and make sure the guest account in your domain is enabled?

You should also check and see if your server is an open relay.
http://www.abuse.net/relay.html

Steve
Expert of the Year 2007
Expert of the Year 2006

Commented:
Are you sure that the messages are coming from your server? You need to see the header information to confirm if they have originated off your machine, or the messages are spoofed.

If you are sure, then it could be either an open relay or authenticated user. If the machine is being used you can usually tell as there will be a large number of messages in the queues.
Authenticated user attacks are usually against the administrator account, so change that account password.
If you don't have any users outside relaying through your server with Outlook Express or similar SMTP product, then you don't even need authenticated relaying and can turn it off.

Simon.

Author

Commented:
i've checked and it is not open for replay. i've looked at the queue and there is no large queue of unknown addresses. here is the header of one of the spam email. i can't tell where it is generated from.

Microsoft Mail Internet Headers Version 2.0
Received: from Robin ([172.30.6.1] RDNS failed) by mail.myserver.com with Microsoft SMTPSVC(6.0.3790.1830);
             Fri, 16 Jun 2006 06:31:51 -0700
Return-path: <firstname_lastname@myserver.com>
Received: from [142.135.192.72] (port=2710 helo=[142.135.192.72])
        by myserver.com with esmtp
        id 0ZKEf4-fZl291-83
        for firstname_lastname@myserver.com; Fri, 16 Jun 2006 08:01:51 -1000
Reply-To: Leanna <firstname_lastname@myserver.com>
Message-ID: <79158161.20060616080151@myserver.com>
From: Leanna <firstname_lastname@myserver.com>
To: <firstname@myserver.com>
Subject: Save your money, buy pills here!
Date: Fri, 16 Jun 2006 08:01:51 -1000
MIME-Version: 1.0
Content-Type: multipart/mixed;
        boundary="----=_NextPart_000_0068_01C4B064.95321943"
X-Priority: 1
X-Mailer: The Bat! (v3.71.14) Home
X-Spam: Not detected
X-OriginalArrivalTime: 16 Jun 2006 13:31:51.0734 (UTC) FILETIME=[39F07D60:01C69149]

------=_NextPart_000_0068_01C4B064.95321943
Content-Type: text/html;
        charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

------=_NextPart_000_0068_01C4B064.95321943
Content-Type: image/gif;
Content-ID: <pOwi8GK9DRX0$HrwYoTHz$AK1WehJLQ@nMpW>
Content-Transfer-Encoding: base64


------=_NextPart_000_0068_01C4B064.95321943--

Author

Commented:
is this where the email sent from?

Received: from [142.135.192.72] (port=2710 helo=[142.135.192.72])

i look at other headers of other spam emails and they are different on each one like this for example:
Received: from [81.229.108.74] (port=1758 helo=[81.229.108.74])

is this server problem or client?

Expert of the Year 2007
Expert of the Year 2006
Commented:
This one is on us!
(Get your first solution completely free - no credit card required)
UNLOCK SOLUTION
Unlock the solution to this question.
Join our community and discover your potential

Experts Exchange is the only place where you can interact directly with leading experts in the technology field. Become a member today and access the collective knowledge of thousands of technology experts.

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

OR

Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.