Re: sending spam

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Just as a point of interest, wireshark puts the NIC in promiscuous mode if it can. Since a server is already handling network traffic from multiple clients, I'm not a fan of running it on a server. A client is usually sufficient for this type of troubleshooting.

But ultimately I'd recommend using firewall logs to track down the offending machine first. If a person is not sure how to track down a machine opening massive SMTP connections, then I think sifting through wireshark's rather verbose logging might be asking a little much out of the gate. :)

-Cliff


"Amnon Feiner" <afeiner@xxxxxx> wrote in message news:48FD01E2.5030904@xxxxxxxxx
Johnfli wrote:
My ISP is telling me that some computer on my network is sending out spam email, at teh rate of about 50,000 per day (their words)

How can I find out what machine is doing that??


In addition, and assuming you handle mail only with your SBS, you can download wireshark and install on your SBS, launch by either clicking the icon or click on capture (one or twe nic?) and look at the logs. That computer will populate.
Onc eyou found it, make sure to install an AV on it (do you have any installed)?

--
Amnon Feiner

.



Relevant Pages

  • Deploying security policies
    ... install it on a shared folder on a server, to be run from multiple clients. ... at runtime by a small "network setup" program that asks for the network ...
    (microsoft.public.dotnet.framework.setup)
  • PPTP , IPSEC/L2TP performance
    ... I've succesfully set up a PPTP server and a IPSEC/L2TP server with ... When i downloaded via the LAN it would go around 1,7 Mb/s with 1 ... When i tried with multiple clients from outside the LAN the ...
    (comp.os.linux.networking)
  • Re: Large performance hit when opening shared network file.
    ... > If you make a single server to perform operations locally there will ... It's even slower than acessing the same file from a network ... If you have multiple clients ...
    (microsoft.public.win32.programmer.networks)
  • Named pipes
    ... the name of the pipe ... - server on Windows XP, client on Windows Server 2003, using ... - server and multiple clients on the same machine using ...
    (microsoft.public.win32.programmer.kernel)
  • Re: 3DES key generation
    ... writing a system that will generate a 3DES key on the server and pass ... it to a service to encrypt a message. ... There will be multiple clients that will receive the encrypted ... Once the key has been passed to a client, it will then decrypt ...
    (sci.crypt)