Hello,

I have been listed in a blacklist and I can't delist myself, because as they say there is spam coming from my IP address. The mail server is also a router.
So far I know I have two scenarios:
1. somebody from the LAN is infected and is sending spam without using the server
2. somebody is using my server

Scenario 1.
I have no clue how to catch the infected machine. Theoretically there should not be any zombie machine because I have up-to-date antivirus on every station. But what if even like that I have a zombie machine? Theoretically if I control the router I should be able to filter all the traffic, but I don't know what application to use, what method to use and what am I looking for?
Any suggestions?

Scenario 2.
Somebody cracked a password of a user and is using the account to send spam. I checked the logs, but there is so much spam traffic, that I don't know what to look for. I don't know exactly how the logs work, but I couldn't find anything interesting. Theoretically in /var/log/qmail/send there should be all the outgoing mails, but I found a lot of spam like subjects here. I presume that those are related to the aliases and forwards. Is this correct?
Please give me a clue what to look for? And how to look for?

Is there other possible scenarios?

Thanks!

---------------------------------------------------------------------
    QmailToaster hosted by: VR Hosted <http://www.vr.org>
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to