Re: SPAMBOT Symptoms?

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Hello,

You need to confirm this is internal or external and also how your
protection is working at present.

I would run a relay test against your server www.abuse.net/relay.html
I would also start Exchange logging on the SMTP and see if the email is
coming from internal or if it is bounce backs generated form your
server, to emails that originally originated externally.

If you suspect it is internal, if you are using ISA, you can track port
25 or deny port 25 from internal workstations. You can also lock
Exchange to not accept smtp from workstations.

As you have a two nic server, i deduce the workstations do not have a
direct route to the internet and must go through the SBS box.

If you still can't find anything internally you can use a packet
sniffing tool like wireshark to see where the SMTP connections are
comming from or from a command prompt on the server, monitor smtp
traffix using "netstat -an" and looking for port 25 traffic.

You can also use nirsoft's cports to check port 25 port activity on
various workstations. It is unlikely they will have anything as they are
more likely connecting via random ports to port 25 on your server but a
lot of the bots are also email servers.

Good luck




Bilbo fakerubbish.domain.org> wrote:

A 2-NIC SBS2003 (SP2), (3GB), has over 80 SMTP Queue entries and
I'm getting email alerts from SBS/Exchange.

Most of these entries seem to be from the same sender.

One queued message in one Queue had a TO:/CC: list of 174 entries --
seems extremely improbable.

I found 3 SMTP Virtual Server Sessions that were Swedish (.SE)
domains. Again, extremely improbable for this company unless this is
where the SPAM senders appear.

This server has been getting hit by significant amounts (~31%) of SPAM
on a daily basis.

This seems to me like a case of a client workstation with a SPAMBOT
running but I'm no expert. Does anyone see it differently?

We're having foul weather here in Houston so I won't be able to be on
site for another 12 hours or so.

The LAN is protected (if that's the word) by Trend Micro CSM 3.6 and I
was planning to evaluate their new product before upgrading this
server and its clients.

Advice gratefully accepted,

-Bilbo


--
Michael J. Jenkin MVP - SBS, MCP, Small Business Specialist, Senior
Systems Engineer
Visit http://www.mickyj.com
.



Relevant Pages

  • RE: RRAS Port configuration
    ... it conencts to the internet via PPPoE and does not get issued an IP ... The server obviously gives it one of those random 169 addresses. ... I am not quite sure about your word "open port 40010". ... SBS clients or server need to access port 40010 on the internet? ...
    (microsoft.public.windows.server.sbs)
  • RE: VBscript Error on SBS2k3
    ... DHCP Server turned of SonicWALL with VPN Pass through request for IP to ... the problem should be caused by the 4125 port. ... > | Accessories and Communications and Remote Desktop Connection? ... > | 2.In Internet Explorer on the workstation you are connecting from, ...
    (microsoft.public.windows.server.sbs)
  • Re: Public Static IP Routing
    ... Right-click on your external / internet nic & select Properties. ... Surveillance), set the incoming port to 1024, the private address to ... Chad A. Gross - SBS MVP ... >> Surveillance server is already being used by something else on your ...
    (microsoft.public.windows.server.sbs)
  • RE: Remote Web Workplace
    ... 825763 How to configure Internet access in Windows Small Business Server ... Port 21 enable external and internal file transfer ... Port 80 enables all nonsecure browser access, ...
    (microsoft.public.windows.server.sbs)
  • RE: RRAS Port configuration
    ... I am not quite sure about your word "open port 40010". ... SBS clients or server need to access port 40010 on the internet? ...
    (microsoft.public.windows.server.sbs)