> So I changed the password for both the mail server and the firewall, > causing the total traffic to drop down to one-third of the previous > amount. Am I being paranoid to consider that suspicious?
Not if you truly have controlled for other factors. But it's a pretty amateur intrusion if it didn't also create backdoors, alternate accounts, etc. Do you have a domain using NT SAM? If so, the Administrator account could have been compromised for AUTH--I saw what looked like traces of this at a client recently--but not to get at actual data. -Sandy To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
