Re: Problems with lots of spam appearing from inet@microsoft.com

From: Stuart Luscombe (stuart.luscombeNOSPAM_at_actifgroup.com)
Date: 12/15/04


Date: Wed, 15 Dec 2004 06:15:01 -0800

Hi,

Thanks for the response.
Unfortunatly, unplugging the server from the outside world isn't a viable
option right
now as various departments here need to be able to contact people overseas
on a
regular basis.

I have found out that this problem is most likely being caused by the Zafi-D
virus,
given that the contents of the e-mails match up to the description.

I assume when you say to look into the mime header to open the file stored
in the
badmail directory?? As if it is, I have done this and am only getting the IP
of our
mailserver show up. I can see the failure reports in the queue, but not the
incoming
messages, so this maybe why I cannot see them. If so, how can I catch the
original
messages as they are coming in before the server tries to bounce them back?

"Stefan Engelbert" wrote:

> First of all I would unplug the network. Otherwise u soon have thousands of
> mails
> in the queue.
> Then I would check/find out the sending IP Number of that mail. You can look
> into
> the mime theader of these mails.
> Then you add these IPs either to your firewall or to your virtual server
> filter.
> Ideally you would also look for an AntiSPAM Solution which can deal with
> your problem like rejecting or not accepting these connections.
> Stefan
>
>
> "Stuart Luscombe" <stuart.luscombeNOSPAM@actifgroup.com> wrote in message
> news:4BA1049C-AB75-40C4-B7BF-754AF6D94287@microsoft.com...
> > Hi everyone,
> >
> > I'm running a single exchange 2000 server for my employer and over the
> past
> > few hours we have been getting a message from inet@microsoft.com which is
> > not actually directed at any one in the company. I'm sure it's not coming
> from
> > Microsoft at all, but I am receiving a new one to the queue every 10
> seconds
> > or
> > so. I would prefer to just block the address from having anything queue on
> the
> > server but cannot work out how to do this or setup a rule so that the mail
> > falls
> > into the same black hole I have setup for any NDR's that come in.
> >
> > Any ideas would be most appreciated, as the queue is currently at 575
> > messages and climbing every second.
> >
> > --
> > Stuart Luscombe
> > Systems Administrator
> > Actif Group plc
> > http://www.actifgroup.com
>
>
>



Relevant Pages

  • Re: Best way to share Thunderbird Profiles across multiple machines.
    ... this setup was done YEARS ago and had followed me through a migration from another distro to Ubuntu 6.06 and now 8.04. ... Postfix then uses procmail sends the mail through spamassassin and server side filtering/sorting (for example, mails from the various mailing lists are directly sent to their directories on the server. ... As for the mails you currently have in your Thunderbird, when you first connect your profile to the IMAP server, you'll see the folders you have now and the folders and the folders on the server. ...
    (Ubuntu)
  • Re: Further problems with exchange on sbs2003.
    ... Right pausing the queue didnt help, ... Nor did restarting the server. ... The way things work here is the pop3 connector picks up various mails from various isp's and puts most directly into user mailboxes. ...
    (microsoft.public.windows.server.sbs)
  • Re: SMTP irritation Exchange Server 2000...
    ... What is "normal" to see in your SMTP queue is debatable. ... you will not see this type of mails. ... person's mail server is down. ... I was mostly joking with my Linux posts. ...
    (microsoft.public.exchange2000.admin)
  • RE: messages remain in queue
    ... > The mails remain in the queue. ... > After this the submitted mails are back in the queue. ... > a Sun Fire V1280 Server ... > The support-team of the unix mail server say that the ...
    (microsoft.public.exchange.connectivity)
  • Re: [SLE] SMTP authentication
    ... So eventhough my local SMTP server dials up to the internet with a certain username and password, that same username and password would not be used as authentication between my local SMTP server and the ISP's one, should it be used as a relay? ... either defer all outgoing mails until you connect to the internet, then flush out all the mails in the queue. ... Your local server would use an external program like fetchmail to poll the mailserver of your ISP, download the mails and feed them to Postfix. ... The test does NOT say "All clients must be in mynetworks, ...
    (SuSE)

Loading