Hello,
I have been listed in a blacklist and I can't delist myself, because as
they say there is spam coming from my IP address. The mail server is
also a router.
So far I know I have two scenarios:
1. somebody from the LAN is infected and is sending spam without using
the server
2. somebody is using my server
Scenario 1.
I have no clue how to catch the infected machine. Theoretically there
should not be any zombie machine because I have up-to-date antivirus on
every station. But what if even like that I have a zombie machine?
Theoretically if I control the router I should be able to filter all the
traffic, but I don't know what application to use, what method to use
and what am I looking for?
Any suggestions?
Scenario 2.
Somebody cracked a password of a user and is using the account to send
spam. I checked the logs, but there is so much spam traffic, that I
don't know what to look for. I don't know exactly how the logs work, but
I couldn't find anything interesting. Theoretically in
/var/log/qmail/send there should be all the outgoing mails, but I found
a lot of spam like subjects here. I presume that those are related to
the aliases and forwards. Is this correct?
Please give me a clue what to look for? And how to look for?
Is there other possible scenarios?
Thanks!
---------------------------------------------------------------------
QmailToaster hosted by: VR Hosted <http://www.vr.org>
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]