Part 2 to this story:

We are still being receiving spam from 7 different mail servers (they are 
trying to relay through our mail server to AOL users), in 17 separate 
attacks (fortunately, our server is not relaying these spams).  It appears 
as though all 7 of these mail servers have been compromised, as the 
spammer-for-hire is running his own software on these mail servers.  Could 
one of them be your server (two of the seven servers are running IMail)?

The spammer-for-hire is apparently breaking into lots of mail servers, and 
installing his spamware there ("Server A").  It has a list of known open 
relays, which it then sends mail to ("Server B").  Those open relays are 
hijacked, and then send the spam to the destination ("Server C").

Because they are running their own spamware on the compromised servers, and 
not using the SMTP server, there are no Received: headers from Server 
A.  The headers from Server B will show the IP address of Server A, but it 
doesn't appear as though the E-mail actually originated there -- it looks 
like it was Server B that was responsible for the E-mail being sent (which 
is partially true, because it is the one that was hijacked).  So, it could 
take a long time before someone realizes that the compromised server 
(Server A) is involved.

And, since the spamware only sends about 400 E-mails at a time to any given 
open relay (Server B), it is unlikely that the server admin will notice the 
spam until they hear something from the recipient.  Given the small volumes 
of mail being sent from any given server, it is likely that there will be 
few complaints, so the server admin might not investigate the situation 
well.  This, of course, means that the spammer can continue sending his 
spam through the open relay.

The morals of the story:

[1] Make sure that you are NOT an open relay.  With IMail, use "Relay for 
Addresses" (search the archive of the forum or the Knowledge Base for 
further details).  If you can't do that for some reason, [shameless plug] 
check out our Declude Hijack.

[2] Make sure that your server can NOT easily be compromised.  Don't run 
IIS without the appropriate patches (remember, if you install the patches 
after you have been compromised, your server is still compromised).

                                                            -Scott

Declude: Anti-virus, Anti-spam and Anti-hijacking solutions for 
IMail.  http://www.declude.com



Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/

Reply via email to