Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Shaun E on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Bogus messages bouncing back!! 1

Status
Not open for further replies.

alfie1noakes

IS-IT--Management
Oct 7, 2002
53
GB
This is the scenario:

I have a server with Exchange 5.5 on Windows NT 4 SP6a (Loaded 6A yesterday). On the desktops I have windows XP Prof, with Office 2000 & Outlook 2000. We are using McAffee TVD, with the Exchange Groupshield on the server, and the desktop version on all the workstations. All workstations and servers are using the latest DAT files.

But, I am getting some strange messages sent back to me, with a my supposed original message attached, from people I have never heard of. They only happen once every couple of days, and I have only had about 5 of these.

The message will be in the form of a "delivery notification status (failure)" or similar. The message body says:

This is an automatically generated Delivery Status Notification.

Delivery to the following recipients failed:


charpentier@di-design.co.uk

Attached to this message is my supposed original message to them, with the my Groupshield Alert TXT file within it.

I am obviuosly not forwarding a virus to anyone, but I appear to be forwarding a message which has had the attachment ripped out of it, to someone I have never heard of. A bit like an open relay.

I have checked our server for open relays, and everything is OK. I have the Exchange Server set to "reroute incoming SMTP mail" and then our domain name set to route to: inbound. Then in "routing restrictions" and "hosts and clients with these IP addresses" is set to be blank.

Sorry its a long one, but I can't think what is going on!!!

Andy
 
That is typical behaviour from a virus. It is spoofing the From address with your address and so the receiving server bounces it to you. The virus could pick up your address from someone infected that had you in their contacts...

Thanks,

Matt Wray

GFH

 
I see, so its not being forwarded by me in any way, but my address is being used in the From address, so then I get the various NDR's.

As long as its nothing for me to worry about, thats fine.

I must say though, I've never had so many instances of viruses hitting the office. Even though we are buttoned up fairly tight, its still causing problems, as I keep having to stop and explain to users what all these alert.txt files are etc.!

And we haven't even been infected by it yet!!

Cheers

Andy
 
Tell me about it! This week and end of last have been terrible. First MyDoom, then Netsky and now this friggin Beagle! Why do these virus writers want to cause so much headache...
[hammer]

Thanks,

Matt Wray

GFH

 
This is exactly why NDR's are a bad idea. They can be used as a form of DoS attack or just be a right pain the @$$.

Chris.


**********************
Chris Andrew, CCNA, CCSA
chris@iproute.co.uk
**********************
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top