Re: SMTSVC ?

From: Jeff Cochran (jeff.nospam_at_zina.com)
Date: 03/26/05

  • Next message: Jason Brown [MSFT]: "Re: Block sites linking to my site"
    Date: Sat, 26 Mar 2005 00:47:29 GMT
    
    

    On Fri, 25 Mar 2005 13:45:05 -0800, "razornt"
    <razornt@discussions.microsoft.com> wrote:

    >Someone is trying to hack our server via SMTPSVC. When I view the event log
    >(system) I see Event ID 100 SMTPSVC and a login attempt. However, when I try
    >to match the Event log time with the SMTPSVC log time nothing matches.

    Are you accounting for the offset from GMT? The SMTP logs are in GMT,
    Event logs are usually in local time.

    Jeff

    > I want
    >to block the IP Address of this potential intruder. How do I find the IP
    >Address of this potential intruder?
    >
    >SMTPSVC extended property logs are turned on with client ip, date and time,
    >server ip and server port and also user name.
    >
    >Default SMTP virtual server
    >No relay (only the list below) "There is no list"
    >Basic and Windows Security package are checked for Authentication
    >
    >Thanks in advance.


  • Next message: Jason Brown [MSFT]: "Re: Block sites linking to my site"

    Relevant Pages

    • Re: Activity M27 motorway
      ... > Steve Firth wrote: ... >> years worth of logs (one entry created about every 10 seconds) until I ... But next time I see an anomaly I'll log time and place! ...
      (uk.local.hampshire)
    • Re: Cut off spam from 127.0.0.1?
      ... When I look at the SMTP logs I don't see times that quite match the ... I do see reference to these message in the Exchange Server ... about the POP3 Connector - in general, no, I don't use the POP3 ...
      (microsoft.public.windows.server.sbs)
    • Re: tracking email viruses to the origin
      ... GFI does not log header info so I have to rely on my ... >>1)Can some one suggest a program or a process to parse my SMTP logs (or ... >>4) Is there a good way to match up my SMTP log or message tracking logs ...
      (microsoft.public.exchange.admin)
    • Re: Cut off spam from 127.0.0.1?
      ... When I look at the SMTP logs I don't see times that quite match the ... I do see reference to these message in the Exchange Server ... I've assumed that there could be a "pickup time ...
      (microsoft.public.windows.server.sbs)
    • Re: multiple inbound messages
      ... msg 6230546 to remote amason@xxxxxxxxxxxx ... Here's a sample of my smtp logs. ... logging for Connection Manager and Queueing Engine in MsExchangeTransport ...
      (microsoft.public.exchange.admin)