?
Solved

possible infected spam server? trying to track down what is sending out spam

Posted on 2011-03-10
5
Medium Priority
?
764 Views
Last Modified: 2013-11-30
I am running exchange 2003 sp2 and have barracuda spam filter filtering inbound and outbound.

pop3
imap
rpc/http is enabled

i have a situation where spam is being sent by my servers. The ip  in the headers are from a foregin country. They are somehow connecting to my email server and sending out spam.

could it be possible that one of my pop/imap users is infected with a virus and authenticating and then seding out spam?

how can i find the offending users.

I turned up loggin on pop3 and imap but do not see the offending ip anywhere.

need help in tracking down the offending user. or can it be my server has a security hole?

i am blocking the spam going outbound from the spam filter but need to get to the bottom
why its sending out.

Thanks in advance


X-ASG-Debug-ID: 1299760893-00f14f5fb10f8d0001-bDo3tZ
X-Barracuda-Envelope-From: dtglvl@tvdirectsat.tv
Received: from User ([207.194.87.105]) by server1.com with Microsoft SMTPSVC(6.0.3790.3959);
       Thu, 10 Mar 2011 07:41:33 -0500
Reply-To: dtglvl@tvdirectsat.tv
X-Barracuda-Apparent-Source-IP: 207.194.87.105
X-Barracuda-BBL-IP: 207.194.87.105
X-Barracuda-RBL-IP: 207.194.87.105
From: Online TV Software<dtglvl@tvdirectsat.tv>
Subject: Watch 9000 World Wide TV Channels on your Computer, TV or SmartPhone
Date: Thu, 10 Mar 2011 14:41:27 +0200
X-ASG-Orig-Subj: Watch 9000 World Wide TV Channels on your Computer, TV or SmartPhone


0
Comment
Question by:mrbrain646
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
5 Comments
 
LVL 76

Accepted Solution

by:
Alan Hardisty earned 2000 total points
ID: 35095096
You are more than likely an authenticated relay and thus this will be bypassing your Barracuda device as it is being allowed through because of authentication.

Please have a read of my article for details of what to do:

http://www.experts-exchange.com/Software/Server_Software/Email_Servers/Exchange/A_2556-Why-are-my-outbound-queues-filling-up-with-mail-I-didn't-send.html
0
 
LVL 4

Author Comment

by:mrbrain646
ID: 35097241
so far so good, i think i found the user account. I will give it a day and see if its the one.

Do you normally turn off logging after? isnt this something that should be on all the time to send to a log server?
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 35097317
Yes - once all has died down - return the logging back to normal otherwise your logs will fill up with not very useful info.

You can have it on all the time if you like, but you may then miss useful log info as they drop off the end of the logs so I would turn it off and only turn it on again if you need to.

You might want to have a read of my two blog entries for some more useful info:

http://alanhardisty.wordpress.com/2010/09/28/increase-in-frequency-of-security-alerts-on-servers-from-hackers-trying-brute-force-password-programs/

http://alanhardisty.wordpress.com/2010/12/01/increase-in-hacker-attempts-on-windows-exchange-servers-one-way-to-slow-them-down/
0
 
LVL 4

Author Closing Comment

by:mrbrain646
ID: 35108655
Thanks for  you expertise.
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 35108668
You are welcome - glad I was able to help and sort your problem out.

Thanks for the points.

Alan
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article will help to fix the below error for MS Exchange server 2010 I. Out Of office not working II. Certificate error "name on the security certificate is invalid or does not match the name of the site" III. Make Internal URLs and External…
Popular third-party chat platforms like Slack, Discord, and Telegram are just a few of the many new productivity applications that are being hijacked by cybercriminals to create command-and-control (C&C) communications infrastructures for their malw…
To show how to generate a certificate request in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Servers >> Certificates…
This video demonstrates how to sync Microsoft Exchange Public Folders with smartphones using CodeTwo Exchange Sync and Exchange ActiveSync. To learn more about CodeTwo Exchange Sync and download the free trial, go to: http://www.codetwo.com/excha…
Suggested Courses
Course of the Month13 days, 13 hours left to enroll

800 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question