Rob, My question to you would be "How can you determine for sure that it's an "inside job"? You mentioned that it could well be the result of the Lentin virus, for one thing. All headers are forgeable, be it by a virus or some malicious outside user. Then again, if you have grounds to suspect that it is one of your customers... :-/
-----Original Message----- From: Rob Weij/QPlus Subject: Re: [IMail Forum] reading syslog Date: Mon, 24 Jun 2002 14:11:33 -0700 Guy, That would mean that the LENTIN VIRUS does it. I looked at my own syslog and found simaler entries. I noticed that the "impersonating" is only done from a hosted-account. Not from foreign (third-party) account. They do not impersonate our mailserver. Might it be that Bonno has to look for someone which has also an access to his mailserver ? Rob Please visit http://www.ipswitch.com/support/mailing-lists.html to be removed from this list. An Archive of this list is available at: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Please visit the Knowledge Base for answers to frequently asked questions: http://www.ipswitch.com/support/IMail/
