Ok so it was a DDOS since it brought our services to a trickle. These messages had "from" lines from msn.com, hotmail.com, yahoo.com and aol.com. There were being sent to other domains that we do not host, many many different ones.
On the binary file I opened it up using a Binary Hex reader but I think it must be a bit more involved. It displays both the hex and the ASCII but I see no values that even resemble an IP address! Has any used a program to view this file that can explain what I need to do to check it? -----Original Message----- From: R. Scott Perry [mailto:[EMAIL PROTECTED] Sent: Tuesday, March 18, 2003 9:48 AM To: [EMAIL PROTECTED] Subject: Re: [IMail Forum] smtpd32.loc hack? >Is it possible for our smtpd32.loc file to get "hacked" or corrupted? We >had a dos attack that came from many diff IP's that are not in our list and >each message was only sent to 3-5 addresses but it was from outside domains >to other outside domains. So either our Relay for addresses is NOT working >or someone has gotten by the security. A DoS attack is a "Denial of Service" attack, which doesn't seem to be the case here. If it was, it would actually be DDoS attack (Distributed Denial of Service). However, it's only a DoS or DDoS attack if you are denied service. In this case, it's a spammer that isn't *intending* on a DDoS attack, but doesn't care if it happens. It is technically only a DDoS attack if your services are affected (such as slow SMTP connections, timeouts, etc.). The key questions here are "Were these E-mails addressed to local users?" (anyone can send unlimited E-mail *to* your users) and "If they were not to local users, did IMail actually relay them?" (if not, IMail handled the situation correctly). >We had this issue 3 months ago but >thought we had resolved the issue but this looks very similar...very >sophisticated. Is there any way we can look at the binary file? The file isn't documented, but it is fairly easy for a knowledgeable person to extract the IP ranges. If the E-mails were relayed, the first thing to check for is something like "192.0.2.25./8", which would allow relaying from any IP beginning with 192. -Scott --- Declude JunkMail: The advanced anti-spam solution for IMail mailservers. Declude Virus: Catches both viruses and vulnerabilities in E-mail, with no annual licensing fees. --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/ To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
