I had to move a box that is hosted for me offsite. I was on 7.15 so installed it on the new box, then moved over my old IMAIL to the new box. Upgraded to 8.05 installed, Declude, anti-virus and so on and then applied HF3.... I have been so badly hacked through the LDAP exploit that I have to move to a new box. He also used my box to scan and compromise other IMAIL servers, I have IPS of possible other hacked IMAIL machines (I'm tempted to post them, but I will try to spend some time when I have it trying to figure out if I can contact these people - unless people feel I should post them) . I have spent over three days pouring through my box, pulling out installed programs, batch files, registry entries and still this guy is running an FTP service on port 4022 that I can't find the program, service or files that are being uploaded and downloaded. The only thing that alerted me to this was the IPNT.NET tech calling me telling me about traffic spikes on my box at 2am.
Virus scans found nothing, spyware scans found nothing. If doing a new install of anything below 8.1 I STRONGLY suggest that you stop the LDAP service immediately and PATCH!!! I had no idea that this exploit was so bad. --- [This E-mail scanned for viruses by Declude Virus] To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
