We ran into a similar situation last week... in our case it was an exploitable Socks proxy. This is a hot technique with spammers right now. (I reported the connecting IPs to the admins, but heard nothing back.) They were hitting 2 open proxies on our network from many machines, delivering to many more open relays.
http://www.theregister.co.uk/content/55/22831.html I got all our open proxies closed. You can scan for them on port 1080, (I think). I don't know of a canned open Socks proxy vulnerability checker. ----- Original Message ----- From: "Mike Kuzenko" <[EMAIL PROTECTED]> To: "Imail Support" <[EMAIL PROTECTED]> Sent: Friday, March 22, 2002 9:33 AM Subject: [IMail Forum] Customer accused of spamming > One of my customers was reported to spamcop for spamming. Please visit http://www.ipswitch.com/support/mailing-lists.html to be removed from this list. An Archive of this list is available at: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Please visit the Knowledge Base for answers to frequently asked questions: http://www.ipswitch.com/support/IMail/
