Solved

HELP... I need to find the internal IP address of an outlook client in Exchange 2003

Posted on 2006-10-24
9
216 Views
Last Modified: 2010-03-06
This is the issue... I may have an outlook client that is sending spam. How can I find out the clients IP that is sending the spam to the exchange server.
I have tried logging and it isn't descrptive enough. The spam has a blank from address so I can't track it that way.

0
Comment
Question by:dheffley
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 4
9 Comments
 
LVL 31

Expert Comment

by:LeeDerbyshire
ID: 17795775
If it is coming from Outlook, then I am sure that the outgoing spam will actually have the correct sender's name, since Exchange always uses the default SMTP address as the sender.  You can probably find the suspected items listed in your outgoing SMTP queues.

Of course, the spam may not be coming from Outlook at all (although that was where the client got infected) - it may be coming from a stand-alone SMTP server installed on the workstation by a trojan.

Are you sure that the spam is actually going through the Exchange server in some way?
0
 

Author Comment

by:dheffley
ID: 17795921
I am fairly sure that it is a client due to the fact that I pay for an external mail relay service and the only machine that has the login information to the service is the exchange server. The Service provides me the originating ip of the email and it is my exchange server.
0
 

Author Comment

by:dheffley
ID: 17795943
I was just thinking after my last post that if a virus gets on a pc; do you think that it could sniff and find an exchange server and utilize it with its own SMTP engine but uses exchange for email routing and delivery?
0
Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

 
LVL 31

Expert Comment

by:LeeDerbyshire
ID: 17795976
Are you sure that it is spam that is originating from your server?  The blank From address might indicate that the mails are simply NDRs sent back out by your server in response to incoming (but badly addressed) spam attempts.  I think it's rare to see spam with no From address, whereas NDRs need a blank From address to avoid creating mail loops.
0
 

Author Comment

by:dheffley
ID: 17796180
That is a possibility... Does exchange send a NDR by default?
0
 
LVL 31

Accepted Solution

by:
LeeDerbyshire earned 250 total points
ID: 17796258
Yes, but you can turn them off in ESM.  Global settings, Internet Message Formats, Default, Advanced, Allow Non-delivery Reports.
0
 

Author Comment

by:dheffley
ID: 17796553
I will check it out and let you know...
0
 

Author Comment

by:dheffley
ID: 17797098
Thanks a million... It was the exchange server sending the NDRs that was causing the issue.
0
 
LVL 31

Expert Comment

by:LeeDerbyshire
ID: 17797386
You're welcome.  It's a very common problem, mistaking NDRs for outgoing spam.
0

Featured Post

[Webinar] Learn How Hackers Steal Your Credentials

Do You Know How Hackers Steal Your Credentials? Join us and Skyport Systems to learn how hackers steal your credentials and why Active Directory must be secure to stop them. Thursday, July 13, 2017 10:00 A.M. PDT

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Unified and professional email signatures help maintain a consistent company brand image to the outside world. This article shows how to create an email signature in Exchange Server 2010 using a transport rule and how to overcome native limitations …
This article will help to fix the below errors for MS Exchange Server 2013 I. Certificate error "name on the security certificate is invalid or does not match the name of the site" II. Out of Office not working III. Make Internal URLs and Externa…
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…
This video demonstrates how to sync Microsoft Exchange Public Folders with smartphones using CodeTwo Exchange Sync and Exchange ActiveSync. To learn more about CodeTwo Exchange Sync and download the free trial, go to: http://www.codetwo.com/excha…

717 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question