Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations bkrike on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Think I'm being used as spam server 1

Status
Not open for further replies.

jmank91

MIS
Feb 22, 2005
45
US
Exchagne Server 5.5 sp3; on NT sp6a; TrendMicro Server Protect w/ ScanMail
Over the past 5 days I have been getting a tremendous amount of email in my exchange server's, D:\exchngsvr\imcdata\out folder. Most of these messages are taiwan destination emails from @hffnet.net and @hinet.net. I've checked and our IP's are not open-relay.
Any help or suggestions with this.
 
Thanks Zelandakh,
I had read over your FAQ yesterday and I am no longer getting nearly as messages in my ./imcdata/out directory but my trendmicro scanmail is still catching almost a messaged a second.

Is there anyway for me to interpret the header on these messages so I can identify the source IP and block its access to my network?
I wish they would fund an upgrade from 5.5 for me but this is all I have to work with.
 
There's nothing wrong with 5.5...
Try netstat on the server to show who is connected. There is a section in ESM to show inbound connections but I can't recall if it goes back to 5.5!
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top