Ok so it was a DDOS since it brought our services to a trickle.

These messages had "from" lines from msn.com, hotmail.com, yahoo.com and
aol.com.  There were being sent to other domains that we do not host, many
many different ones.  

On the binary file I opened it up using a Binary Hex reader but I think it
must be a bit more involved.  It displays both the hex and the ASCII but I
see no values that even resemble an IP address!  Has any used a program to
view this file that can explain what I need to do to check it?



-----Original Message-----
From: R. Scott Perry [mailto:[EMAIL PROTECTED]
Sent: Tuesday, March 18, 2003 9:48 AM
To: [EMAIL PROTECTED]
Subject: Re: [IMail Forum] smtpd32.loc hack?



>Is it possible for our smtpd32.loc file to get "hacked" or corrupted?  We
>had a dos attack that came from many diff IP's that are not in our list and
>each message was only sent to 3-5 addresses but it was from outside domains
>to other outside domains.  So either our Relay for addresses is NOT working
>or someone has gotten by the security.

A DoS attack is a "Denial of Service" attack, which doesn't seem to be the 
case here.  If it was, it would actually be DDoS attack (Distributed Denial 
of Service).  However, it's only a DoS or DDoS attack if you are denied 
service.  In this case, it's a spammer that isn't *intending* on a DDoS 
attack, but doesn't care if it happens.  It is technically only a DDoS 
attack if your services are affected (such as slow SMTP connections, 
timeouts, etc.).

The key questions here are "Were these E-mails addressed to local users?" 
(anyone can send unlimited E-mail *to* your users) and "If they were not to 
local users, did IMail actually relay them?" (if not, IMail handled the 
situation correctly).

>We had this issue 3 months ago but
>thought we had resolved the issue but this looks very similar...very
>sophisticated.  Is there any way we can look at the binary file?

The file isn't documented, but it is fairly easy for a knowledgeable person 
to extract the IP ranges.

If the E-mails were relayed, the first thing to check for is something like 
"192.0.2.25./8", which would allow relaying from any IP beginning with 192.

                                                    -Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers.
Declude Virus: Catches both viruses and vulnerabilities in E-mail, with no 
annual licensing fees.

---
[This E-mail was scanned for viruses by Declude Virus
(http://www.declude.com)]


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to