Wilders Security Forums  

Go Back   Wilders Security Forums > Privacy Related Topics > privacy problems
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old October 23rd, 2003, 05:05 AM
martindijk's Avatar
martindijk martindijk is offline
Frequent Poster
 
Join Date: Jun 2003
Location: Gorredijk - the Netherlands
Posts: 537
Default Email server hacked??

Hi all,

Didn't know what hit me yesterday, as always i checked my email on my Win2000 server and i received 2100 mails back from the Postmaster.

All adresses were send to different names but always a "hotmail" domain.

Now it seems a korean guy is using my mailserver to propagate spam and everytime i check my mail i get hundreds of returned mail from the postmaster and our own internal mail can not be received anymore as a result of all those "hotmail" returned messages.

For now i have reconfigured the email server, but i haven't got a clue what is generating all this mail

Could this be the affect of a browser hack or something like that.

Please help me out here guys, any suggestion is welcome.

Thanks in advance,

cheers,
Martin
__________________
Thanks,
Martin

My software never has bugs ~ It just develops random features
  #2  
Old October 23rd, 2003, 05:12 AM
Pieter_Arntz's Avatar
Pieter_Arntz Pieter_Arntz is offline
Spyware Veteran
 
Join Date: Apr 2002
Location: Netherlands
Posts: 12,716
Default Re:Email server hacked??

Hi Martin,

Have you checked your list of processes for anything suspicious?
I have seen reports of trojan-like programs turning computers into spam relayers.

Regards,

Pieter
__________________
Regards,

Pieter
Itīs nice to be important, but itīs more important to be nice.

It's human to make mistakes. It's even more so to blame the computer for it.
  #3  
Old October 23rd, 2003, 05:19 AM
martindijk's Avatar
martindijk martindijk is offline
Frequent Poster
 
Join Date: Jun 2003
Location: Gorredijk - the Netherlands
Posts: 537
Default Re:Email server hacked??

Hi Pieter,

Done that and at first glance it seems to be oké.

Is it worth running Hijack This on the server and have it checked out on this forum

rgds,
Martin
__________________
Thanks,
Martin

My software never has bugs ~ It just develops random features
  #4  
Old October 23rd, 2003, 05:46 AM
Pieter_Arntz's Avatar
Pieter_Arntz Pieter_Arntz is offline
Spyware Veteran
 
Join Date: Apr 2002
Location: Netherlands
Posts: 12,716
Default Re:Email server hacked??

Hi Martin,

I'd be happy to have a look if I can find something.

Regards,

Pieter
__________________
Regards,

Pieter
Itīs nice to be important, but itīs more important to be nice.

It's human to make mistakes. It's even more so to blame the computer for it.
  #5  
Old October 23rd, 2003, 08:07 AM
DiGi's Avatar
DiGi DiGi is offline
Regular Poster
 
Join Date: Jul 2003
Location: in the middle of nowhere
Posts: 114
Default Re:Email server hacked??

Maybe it was only wrong configured smtp server (open relay)...

Check http://www.ordb.org/
__________________
www.qr.cz - news 4 u
  #6  
Old October 23rd, 2003, 08:14 AM
martindijk's Avatar
martindijk martindijk is offline
Frequent Poster
 
Join Date: Jun 2003
Location: Gorredijk - the Netherlands
Posts: 537
Default Re:Email server hacked??

Hi DiGi,

Can you please tell me what that means to me : an open relay, and how this can solve my earlier mentioned problems??

cheers,
Martin
__________________
Thanks,
Martin

My software never has bugs ~ It just develops random features
  #7  
Old October 23rd, 2003, 08:29 AM
JayK JayK is offline
Poster
 
Join Date: Dec 2002
Posts: 619
Default Re:Email server hacked??

Quote:
quoting: Martin vDijk link=board=21;threadid=15309;start=0#msg95578 date=1066911296]
Hi DiGi,

Can you please tell me what that means to me : an open relay, and how this can solve my earlier mentioned problems??

cheers,
Martin

If your mailserver is a open relay, it means anyone can send email from your smtp server.

Spammers love that of course.

Normally, you would have restrictions on who can use your smtp server, either by limiting by ip , or by allowing mail after a pop authication etc

  #8  
Old October 23rd, 2003, 08:34 AM
JayK JayK is offline
Poster
 
Join Date: Dec 2002
Posts: 619
Default Re:Email server hacked??

Another possibility (depending on the type of messages you are getting), some did a joe job on you.

IE someone spoofed your email addie by changing the
"Reply To" address .

You can't do much in this case.
  #9  
Old October 23rd, 2003, 09:15 AM
martindijk's Avatar
martindijk martindijk is offline
Frequent Poster
 
Join Date: Jun 2003
Location: Gorredijk - the Netherlands
Posts: 537
Default Re:Email server hacked??

Thanks all for your replies,

Is there an easy way of closing this open relay??

cheers,
Martin
__________________
Thanks,
Martin

My software never has bugs ~ It just develops random features
  #10  
Old October 23rd, 2003, 09:20 AM
JayK JayK is offline
Poster
 
Join Date: Dec 2002
Posts: 619
Default Re:Email server hacked??

Quote:
quoting: Martin vDijk link=board=21;threadid=15309;start=0#msg95592 date=1066914955]
Thanks all for your replies,

Is there an easy way of closing this open relay??

cheers,
Martin

?? It depends on what mail server you are running. No offence but if you don't know what an open relay is , you really shouldnt be running a mail server.

Lots of security issues....
  #11  
Old October 23rd, 2003, 09:34 AM
martindijk's Avatar
martindijk martindijk is offline
Frequent Poster
 
Join Date: Jun 2003
Location: Gorredijk - the Netherlands
Posts: 537
Default Re:Email server hacked??

Iam running a Cobalt Cube 3, and as for the open relay aspect, it is just the english terms that confuses me, that's all.

cheers,
Martin
__________________
Thanks,
Martin

My software never has bugs ~ It just develops random features
  #12  
Old October 23rd, 2003, 09:38 AM
JayK JayK is offline
Poster
 
Join Date: Dec 2002
Posts: 619
Default Re:Email server hacked??

Quote:
quoting: Martin vDijk link=board=21;threadid=15309;start=0#msg95598 date=1066916078]
Iam running a Cobalt Cube 3, and as for the open relay aspect, it is just the english terms that confuses me, that's all.

cheers,
Martin

Sorry. never heard of it. Try checking your documentation. Also are you certain yours is an open relay?
  #13  
Old October 27th, 2003, 02:58 PM
4NodAu 4NodAu is offline
Infrequent Poster
 
Join Date: Oct 2003
Posts: 6
Default Re:Email server hacked??

Hi,
VIEW: Thank U Nod32 Staff x 2 4NodAu ( Posted Tuesday 28th October 2003 Australian Time )

************

VIEW : http://www.sacm.co.za/Feature.asp?NewsID=6828&Cont=News

THIS NASTY CAME BY WAY OF AN OFFICIAL LOOKIN' MICROSOFT EMAIL PATCH FOR IE V'S 4.01 - 6.xx and win 95 - win xp.

MAYBE these ISP'S have got umpteen WORMS - TROJANS - VIRUSES imbedded and nasty TERRISTO'S are REMOTELY CONTROLLING THE SERVERS AND / OR DUMPING AND email ADDIES to these

BULK SENDERS OF EMAIL UNSOLICITED AND OR SPAMMMERS !!!

USE ADAWARE AND ALWAYS QUARANTIENE EVERYTHING CHECK IT IS ALWAYS ON. HURISTIC AND DEEP SCAN ON.

CHOOSE TO LEAVE ON SERVER AND MOVE TO TRASH ON EXIT SOUNDS A GOOD IDEA.

PERHAPS THE HACKERS HAVE THE ISP SERVERS SETUP TO KEEP PILES OF EMAILS THAT SHOULD HAVE BEEN DELETED ... THEN DUMP THEM ON US.


********************************

WE RECEIVED 20 + OF EXACTLY THE SAME BLOODY EMAIL FROM EXACTLY THE SAME SOURCE.

********************************

regards
4NodAu
  #14  
Old October 27th, 2003, 03:04 PM
4NodAu 4NodAu is offline
Infrequent Poster
 
Join Date: Oct 2003
Posts: 6
Default Re:Email server hacked??

Hi,
By the way ... MAYBE why you copped them back was that everyone's email server mail boxes were chockers like ours at telstra bigpond.com.au here in Aussie we were 101% FULL UP AND OVERFLOWING. WE WERE ADVISED BY EMAIL THAT THE BIGPOND SERVER WOULD REJECT ANY FURTHER EMAILS TO OUR ADDIE AND TO CLEAN OUT OR EMAIL BOX.

BLOODY NETSCAPE GOES IN EVER 10 MINUTES AND GETS OUR EMAILS !!

IT WAS JUST EMAIL KAYOS !!


regards
4NodAu.
  #15  
Old October 29th, 2003, 12:17 PM
martindijk's Avatar
martindijk martindijk is offline
Frequent Poster
 
Join Date: Jun 2003
Location: Gorredijk - the Netherlands
Posts: 537
Default Re:Email server hacked??

@Pieter, maybe you can find something, thanks in advance.

cheers,
Martin
__________________
Thanks,
Martin

My software never has bugs ~ It just develops random features
  #16  
Old October 29th, 2003, 02:03 PM
Pieter_Arntz's Avatar
Pieter_Arntz Pieter_Arntz is offline
Spyware Veteran
 
Join Date: Apr 2002
Location: Netherlands
Posts: 12,716
Default Re:Email server hacked??

Hi Martin,

Perfectly normal log for a Compaq ProLiant server.

Regards,

Pieter
__________________
Regards,

Pieter
Itīs nice to be important, but itīs more important to be nice.

It's human to make mistakes. It's even more so to blame the computer for it.
  #17  
Old October 30th, 2003, 07:56 AM
martindijk's Avatar
martindijk martindijk is offline
Frequent Poster
 
Join Date: Jun 2003
Location: Gorredijk - the Netherlands
Posts: 537
Default Re:Email server hacked??

Hi Pieter,

Thanks for letting me know, i appreciate it.

cheers,
Martin
__________________
Thanks,
Martin

My software never has bugs ~ It just develops random features
 

Wilders Security Forums > Privacy Related Topics > privacy problems « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 03:58 PM.


Powered by vBulletinŪ Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright Đ2002 - 2013, Wilders Security Forums