Re: Mass Mailing worm problem, please help

From: Chuck (none_at_example.net)
Date: 08/27/04


Date: 27 Aug 2004 13:48:14 -0500

On Fri, 27 Aug 2004 20:28:11 +0800, "chris" <router88@sinaman.com> wrote:

>Hi All,
>
>I got a very serious problem. My email server keep having the "relaying
>denied" message and I think some of my clients' pc got infected. However,
>the email didn't show which pc or from which IP address the email are sent
>from. Therefore, I would like to know how can I check it out or any software
>can help??? And also, how can I identify which virus my clients' pc are
>infected. As it made us can't send out any email with message below
>
>Mail server: WinRoute Pro 4.2.5 at ctw.com.hk
>Error description: message could not be delivered, server replied:
>550 5.7.1 <teix@ter.hk>... Relaying denied
>Original message is attached.
>
>Anyone can help?? Please help me...Thanks alot.
>
>Chris

Chris,

So were there not any clues in the "Original message is attached"?

If your client has a PC that's busy sending out spam, there should be a lot of
smtp traffic on their LAN. Hoping that they're behind a firewall or router, is
there not a firewall log?

What hub / switch is their LAN based upon? If a switch, can you install a hub
between it and the internet gateway, and setup a sniffer listening for outgoing
smtp traffic?

Cheers,
Chuck
Paranoia comes from experience - and is not necessarily a bad thing.



Relevant Pages

  • Network hanging - event id 1058, 1000 client side
    ... newly installed network cabling, new hardware, 3com 16 port ... a few clients get hung up when ... but that seems hard to fix without being able to replace the switch. ... Visit Topic URL to contact author (reg. ...
    (microsoft.public.win2000.general)
  • SUMMARY: Sol8 / netraX1 / packet loss
    ... network autonegotiation between the netras and the cisco switch. ... The netras decided they had 100MHz full duplex, the switch decided 10MHz ... > All the clients were installed using jumpstart and a common OS image. ...
    (SunManagers)
  • Sol8 / netraX1 / packet loss
    ... X1/Solaris 8) via a Cisco Catalyst 2950 switch. ... The switch forms a private network used only for NFS traffic. ... All the clients were installed using jumpstart and a common OS image. ... A few weeks ago we noticed NFS problems on two of the clients. ...
    (SunManagers)
  • Re: Limited connectivity
    ... You are talking about RRAS, so how did the clients connect, remote over VPN or in your local network? ... If they are at the same switch like the server and you gave them fixed ip configuration, can you ping the server via ip and computername? ... computers decided they wouldn't renew their leases, ...
    (microsoft.public.windows.server.networking)
  • Re: NLB Reverse Proxy
    ... Wenn der Router Pakete an das Cluster ... soll man das Cluster auf einen Hub und diesen dann auf den Switch stecken. ... Welche Regel zieht denn da? ... > Sind beide Clients Webproxyclients oder SecureNAT Clients? ...
    (microsoft.public.de.german.isaserver)