I think this is what you need and after looking at this I see how they
got through.  They either guessed the test username and password or got
it some other way?  I see that they change the from address every so
often during the process, would hijack still catch that?


03:10 00:42 SMTPD(00000590) Authenticated [EMAIL PROTECTED], session treated as local.

Let me guess -- the password is "password" or "test"? It seems that several spammers have tried that lately.


But yet, Declude Hijack would catch this, as it looks at the IP address of the E-mail, rather than the return address.

-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers.
Declude Virus: Catches both viruses and vulnerabilities in E-mail, with no annual licensing fees.


---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to