> So I changed the password for both the mail server and the firewall,
> causing  the total traffic to drop down to one-third of the previous
> amount.  Am  I  being  paranoid  to  consider that suspicious?

Not  if you truly have controlled for other factors. But it's a pretty
amateur  intrusion  if  it  didn't  also  create  backdoors, alternate
accounts,  etc.  Do  you  have  a  domain  using  NT  SAM?  If so, the
Administrator account could have been compromised for AUTH--I saw what
looked  like  traces  of  this at a client recently--but not to get at
actual data.

-Sandy


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to