Re: stop spamming



Can you pull the logs from your firewall? They should show any outbound
port 25 traffic, and what the originating IP is...


"Rod" <camino.april@xxxxxxxxxx> wrote in message
news:%23P%23hTcv$FHA.436@xxxxxxxxxxxxxxxxxxxxxxx
> I have just done what yuo suggested.
> Could I know which Private IP of my LAN is sending emails, because
> infected, watching in the router ?
>
>
> "Tom Felts" <tfelts@xxxxxxxxxxxxxxxxxxxxxx> ha scritto nel messaggio
> news:u4oZmbm$FHA.3392@xxxxxxxxxxxxxxxxxxxxxxx
> > Do you have AV on all your destops\servers? Sober U has it's own SMTP
> > engine, so it may not be going through your exchange server, but may be
> > going outbound through your firewall....can you block all outbound port
> > 25,
> > except for your exchange server?
> >
> >
> > "Rod" <camino.april@xxxxxxxxxx> wrote in message
> > news:urdtfHm$FHA.4012@xxxxxxxxxxxxxxxxxxxxxxx
> >> It seems that originating IP is mine (85.32.159.27).
> >> At the header of the email there is my IP (see above)
> >>
> >> "Tom Felts" <tfelts@xxxxxxxxxxxxxxxxxxxxxx> ha scritto nel messaggio
> >> news:%23LNt41l$FHA.740@xxxxxxxxxxxxxxxxxxxxxxx
> >> > There is a third possibility:
> >> >
> >> > Somone in the world has the virus, and is SPOOFING your domain as the
> >> > sender. The way to verify is to look at the headers of the e-mail
sent
> > to
> >> > rossi@xxxxxxxxxx What is the originating IP? Is it yours? If not,
it
> > is
> >> > spoofed (which sober does, btw).
> >> >
> >> >
> >> > Sounds like rossi@xxxxxxxxx needs a good AV solution.
> >> >
> >> >
> >> > "Rod" <camino.april@xxxxxxxxxx> wrote in message
> >> > news:%2350xtpl$FHA.328@xxxxxxxxxxxxxxxxxxxxxxx
> >> >> Hi at all!
> >> >> I have this configuration:
> >> >> MailServer (Exchange 2003) ----> Firewall (Watchguard Firebix
> > X) ----->
> >> >> Router Telecom ---> Internet
> >> >> I have MCcafee antivirus.
> >> >>
> >> >> My problem is:
> >> >> A person with this email "rossi@xxxxxxxxx" is receiving, one eache
16
> >> >> minutes, emails containing WORM.SOBER.U virus, from my smtp server.
> >> >> I think there are 2 reasons:
> >> >> a) I have the virus and send the email
> >> >> Analizing the smtp log of Exchange server 2003, I have no
> >> >> emails
> >> >> forwarded to rossi@xxxxxxxxx
> >> >>
> >> >> b) Someone in the world has the virus that use my server as SMTP
> > server
> >> > to
> >> >> send email containing the virus..
> >> >> How could I see this connections to my server ?
> >> >> How could I deny the access ?
> >> >>
> >> >> Could anyone help me, please?
> >> >> Regards,
> >> >> Antonio Grasso
> >> >>
> >> >>
> >> >
> >> >
> >>
> >>
> >
> >
>
>


.



Relevant Pages

  • Re: Spam Problem
    ... postmaster as the originating email address then you have a dictionary ... Exchange Server accepts aliases to valid domains at your exchange server. ... Messages placed in the bad mail directory can't be ... are falsified the NDRs sit in the outbound queue (outbound with originating ...
    (microsoft.public.exchange2000.general)
  • Re: published mail server behind 2006 cannot telnet out on port 25?
    ... I tried creating an outbound access rule (port 25 of internal ... From the outside, POP3 works, and SMTP can be used to send an email to ... But, the Exchange Server cannot send emails to the outside world, they ...
    (microsoft.public.isa)
  • Re: Exchange Server 5.5 Spam??
    ... If is the originating email address of the outbound emails then they are ... Exchange Server accepts aliases to valid domains at your exchange server. ...
    (microsoft.public.exchange.admin)
  • Re: NULL Originator killing outbound queue?
    ... If is the originating email address of the outbound emails then they are ... Exchange Server accepts aliases to valid domains at your exchange server. ... Exchange Server attempts to deliver NDRs ...
    (microsoft.public.exchange.admin)
  • Re: 5.5 message queue
    ... If is the originating email address of the outbound emails then they are ... Exchange Server accepts aliases to valid domains at your exchange server. ... Exchange Server attempts to deliver NDRs ...
    (microsoft.public.exchange.admin)