I was listed by dnsbl.

DNSBL stands for DNS BlackList. It is a term used to replace RBL (which many people still use, but should not because it is trademarked by MAPS). There are hundreds of DNSBLs (see http://www.declude.com/junkmail/support/ip4r.htm ). What we need to know is which one listed you (SPAMCOP, DSBL, etc.).


The port was open in both directions.

That is not good. Your firewall should block all incoming traffic to all ports on the mailserver except those that are needed.


I have applied an inbound and outbound block for all ip's on that port to my email server.

That is a good start -- if your mailserver is indeed infected, it should help ensure that the people that control the virus cannot access your server.


If it's open on the server, what is the easiest way to close it? If you go to http://www.dnsbl.sorbs.net/cgi-bin/lookup?IP=66.231.32.24 ...

Ah, that's SORBS-WEB that you are listed in.

The problem isn't that there is an open port. For example, IMail has port 25 open. If you did not want people accessing the mailserver, you could just close port 25 on your firewall -- but IMail would still run. In this case, the virus presumably has port 10000 open, in which case you would need to disable the virus in order for it to no longer listen on port 10000.

SORBS is pretty reliable, so I would run AV software to see if the server is infected, and if so, remove it.

-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers since 2000.
Declude Virus: Ultra reliable virus detection and the leader in mailserver vulnerability detection.
Find out what you've been missing: Ask for a free 30-day evaluation.


---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to