Thank you Guys for the explanation
Looks like the binary file is fine there was no other additional entries and
the ones in there looked good, they matched what was displayed in the IMail
admin.  So if we assume the Relay for Address is working then...

I finally spoke to the guys who where working on this late last night.  They
suggest that these spammers are forging there IP's, since they are not
listed in our address list and our server is allowing this.  Sorry I'm such
a novice but is this possible and if so how would we guard against this?
Wouldn't the server be able to tell that this was forged??

Thank you again
Dustin





-----Original Message-----
From: Smart Business Lists [mailto:[EMAIL PROTECTED]
Sent: Tuesday, March 18, 2003 11:25 AM
To: Dustin Freeman
Subject: Re: [IMail Forum] smtpd32.loc hack?


Dustin,

Tuesday, March 18, 2003 you wrote:
DF> On the binary file I opened it up using a Binary Hex reader but I
DF> think it must be a bit more involved.

    No, it is 4 bytes IP address followed by 4 bytes Mask address.
    The end of the current list is delimited by 8 bytes of h00.

DF> It displays both the hex and the ASCII but I see no values that
DF> even resemble an IP address!

    Well that may mean a problem.

DF> Has any used a program to view this file that can explain what I
DF> need to do to check it?

    1) IMAIL gui
    2) IMAIL monitor program from the web - usually 8181
    3) hex editor

Terry


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to