Part 2 to this story:
We are still being receiving spam from 7 different mail servers (they are
trying to relay through our mail server to AOL users), in 17 separate
attacks (fortunately, our server is not relaying these spams). It appears
as though all 7 of these mail servers have been compromised, as the
spammer-for-hire is running his own software on these mail servers. Could
one of them be your server (two of the seven servers are running IMail)?
The spammer-for-hire is apparently breaking into lots of mail servers, and
installing his spamware there ("Server A"). It has a list of known open
relays, which it then sends mail to ("Server B"). Those open relays are
hijacked, and then send the spam to the destination ("Server C").
Because they are running their own spamware on the compromised servers, and
not using the SMTP server, there are no Received: headers from Server
A. The headers from Server B will show the IP address of Server A, but it
doesn't appear as though the E-mail actually originated there -- it looks
like it was Server B that was responsible for the E-mail being sent (which
is partially true, because it is the one that was hijacked). So, it could
take a long time before someone realizes that the compromised server
(Server A) is involved.
And, since the spamware only sends about 400 E-mails at a time to any given
open relay (Server B), it is unlikely that the server admin will notice the
spam until they hear something from the recipient. Given the small volumes
of mail being sent from any given server, it is likely that there will be
few complaints, so the server admin might not investigate the situation
well. This, of course, means that the spammer can continue sending his
spam through the open relay.
The morals of the story:
[1] Make sure that you are NOT an open relay. With IMail, use "Relay for
Addresses" (search the archive of the forum or the Knowledge Base for
further details). If you can't do that for some reason, [shameless plug]
check out our Declude Hijack.
[2] Make sure that your server can NOT easily be compromised. Don't run
IIS without the appropriate patches (remember, if you install the patches
after you have been compromised, your server is still compromised).
-Scott
Declude: Anti-virus, Anti-spam and Anti-hijacking solutions for
IMail. http://www.declude.com
Please visit http://www.ipswitch.com/support/mailing-lists.html
to be removed from this list.
An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/