SMTSVC ?

From: razornt (razornt_at_discussions.microsoft.com)
Date: 03/25/05


Date: Fri, 25 Mar 2005 13:45:05 -0800

Someone is trying to hack our server via SMTPSVC. When I view the event log
(system) I see Event ID 100 SMTPSVC and a login attempt. However, when I try
to match the Event log time with the SMTPSVC log time nothing matches. I want
to block the IP Address of this potential intruder. How do I find the IP
Address of this potential intruder?

SMTPSVC extended property logs are turned on with client ip, date and time,
server ip and server port and also user name.

Default SMTP virtual server
No relay (only the list below) "There is no list"
Basic and Windows Security package are checked for Authentication

Thanks in advance.



Relevant Pages

  • Re: SMTSVC ?
    ... Thanks Jeff. ... >>Someone is trying to hack our server via SMTPSVC. ... >>to match the Event log time with the SMTPSVC log time nothing matches. ...
    (microsoft.public.inetserver.iis.security)
  • Re: What are the best general things to do after a dirty shutdown (Server SBS)
    ... Microsoft Windows Small Business Server 2003 Best Practices Analyzer ... After that, please post any event log errors, just the EventID# and Source names, not the whole error message. ... error 15100 Win32 Error 15100. ... One is indicating it can't retrieve info about the System log. ...
    (microsoft.public.windows.server.sbs)
  • Re: What are the best general things to do after a dirty shutdown (Server SBS)
    ... test network connectivity to local domain controllers. ... Directory Server Diagnosis ... Verifying that the local machine ALPHA, ... The File Replication Service Event log test ...
    (microsoft.public.windows.server.sbs)
  • Re: What are the best general things to do after a dirty shutdown (Server SBS)
    ... Microsoft Windows Small Business Server 2003 Best Practices Analyzer ... After that, please post any event log errors, just the EventID# and Source names, not the whole error message. ... (Event String (event log = Directory Service) ...
    (microsoft.public.windows.server.sbs)
  • Re: Server2003 2008 error !!
    ... Remove the x.x.1.x form the NIC of the DCs and configure it as a FORWARDER or use directly the ISPs DNS server as Forwarders in the DNS server properties in the DNS management console. ... On the 2008 make sure the internal firewall is not blocking AD replication, by default the firewall is enabled ion 2008. ... The event log File Replication Service on server ... EventID: 0x000003EE ...
    (microsoft.public.windows.server.active_directory)