Scott, do you have any links on information on what to do if the iis
computer has been compromised, patch installed, whats next to remove it?
TIA
> [2] Make sure that your server can NOT easily be compromised. Don't run
> IIS without the appropriate patches (remember, if you install the patches
> after you have been compromised, your server is still compromised).
>
> -Scott
>
> Declude: Anti-virus, Anti-spam and Anti-hijacking solutions for
> IMail. http://www.declude.com
> -----Original Message-----
> From: [EMAIL PROTECTED]
> [mailto:[EMAIL PROTECTED]]On Behalf Of R. Scott Perry
> Sent: Tuesday, July 24, 2001 10:26 AM
> To: [EMAIL PROTECTED]
> Subject: Re: [IMail Forum] 6 spam attacks in 24 hours
> (distributedspamming?)
>
>
> Part 2 to this story:
>
> We are still being receiving spam from 7 different mail servers (they are
> trying to relay through our mail server to AOL users), in 17 separate
> attacks (fortunately, our server is not relaying these spams).
> It appears
> as though all 7 of these mail servers have been compromised, as the
> spammer-for-hire is running his own software on these mail
> servers. Could
> one of them be your server (two of the seven servers are running IMail)?
>
> The spammer-for-hire is apparently breaking into lots of mail
> servers, and
> installing his spamware there ("Server A"). It has a list of known open
> relays, which it then sends mail to ("Server B"). Those open relays are
> hijacked, and then send the spam to the destination ("Server C").
>
> Because they are running their own spamware on the compromised
> servers, and
> not using the SMTP server, there are no Received: headers from Server
> A. The headers from Server B will show the IP address of Server
> A, but it
> doesn't appear as though the E-mail actually originated there -- it looks
> like it was Server B that was responsible for the E-mail being
> sent (which
> is partially true, because it is the one that was hijacked). So,
> it could
> take a long time before someone realizes that the compromised server
> (Server A) is involved.
>
> And, since the spamware only sends about 400 E-mails at a time to
> any given
> open relay (Server B), it is unlikely that the server admin will
> notice the
> spam until they hear something from the recipient. Given the
> small volumes
> of mail being sent from any given server, it is likely that there will be
> few complaints, so the server admin might not investigate the situation
> well. This, of course, means that the spammer can continue sending his
> spam through the open relay.
>
> The morals of the story:
>
> [1] Make sure that you are NOT an open relay. With IMail, use "Relay for
> Addresses" (search the archive of the forum or the Knowledge Base for
> further details). If you can't do that for some reason, [shameless plug]
> check out our Declude Hijack.
>
> [2] Make sure that your server can NOT easily be compromised. Don't run
> IIS without the appropriate patches (remember, if you install the patches
> after you have been compromised, your server is still compromised).
>
> -Scott
>
> Declude: Anti-virus, Anti-spam and Anti-hijacking solutions for
> IMail. http://www.declude.com
>
>
>
> Please visit http://www.ipswitch.com/support/mailing-lists.html
> to be removed from this list.
>
> An Archive of this list is available at:
> http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
>
>
Please visit http://www.ipswitch.com/support/mailing-lists.html
to be removed from this list.
An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/