SatPhone - 717.633.3823
Roshain Mobile - 079 - 736 - 3832
Molōn labe!
From: Sherry Abercrombie [mailto:saber...@gmail.com]
Sent: Wednesday, July 22, 2009 7:53 PM
To: MS-Exchange Admin Issues
Subject: Re: Making sure all can read... (was RE: 2k3 message tracking-Resolved)
LOL, it worked
Exactly.
Almost all of the unix tools have a meaningful (if non-obvious) name.
-sc
From: Michael B. Smith [mailto:mich...@owa.smithcons.com]
Sent: Wednesday, July 22, 2009 6:22 PM
To: MS-Exchange Admin Issues
Subject: RE: 2k3 message tracking-Resolved
grep - global regular
ginal Message-
>> > From: Sherry Abercrombie [mailto:saber...@gmail.com]
>> > Sent: Wednesday, July 22, 2009 15:10
>> > To: MS-Exchange Admin Issues
>> > Subject: Re: 2k3 message tracking-Resolved
>> >
>> > LOL, well, usually only someone wi
True 'nuff. Wuss works - can't even bowl without beering (can beer
without bowling tho).
From: Michael B. Smith [mailto:mich...@owa.smithcons.com]
Sent: Wednesday, July 22, 2009 3:20 PM
To: MS-Exchange Admin Issues
Subject: RE: 2k3 message trackin
grep - global regular expression print (i think - close anyway)
vi - visual editor
Both make sense to me.
From: Steven M. Caesare [scaes...@caesare.com]
Sent: Wednesday, July 22, 2009 6:21 PM
To: MS-Exchange Admin Issues
Subject: RE: 2k3 message tracking-Resolved
You don't need grep.
You've got Powershell, and select-string.
From: Sherry Abercrombie [mailto:saber...@gmail.com]
Sent: Wednesday, July 22, 2009 2:10 PM
To: MS-Exchange Admin Issues
Subject: Re: 2k3 message tracking-Resolved
LOL, well, usually on
It isn't?
It is?
-sc
From: Don Andrews [mailto:don.andr...@safeway.com]
Sent: Wednesday, July 22, 2009 4:31 PM
To: MS-Exchange Admin Issues
Subject: RE: 2k3 message tracking-Resolved
Yup, grep is quite a tool if not meaningfully named - like vi - at least
tail gives you a
Wuss.
Vi (vim) is my preferred editor. It rocks!
From: Don Andrews [don.andr...@safeway.com]
Sent: Wednesday, July 22, 2009 5:07 PM
To: MS-Exchange Admin Issues
Subject: RE: 2k3 message tracking-Resolved
Agree wholeheartedly – am very happy to be able to say I
Agree wholeheartedly - am very happy to be able to say I no longer have
any access to our *nix servers.
From: Sherry Abercrombie [mailto:saber...@gmail.com]
Sent: Wednesday, July 22, 2009 1:34 PM
To: MS-Exchange Admin Issues
Subject: Re: 2k3 message tracking
Sure thing.
I'd appreciate seeing the log of a session.
Glen.
-Original Message-
From: pramatow...@mediageneral.com [mailto:pramatow...@mediageneral.com]
Sent: Wednesday, July 22, 2009 2:01 PM
To: MS-Exchange Admin Issues
Subject: RE: 2k3 message tracking-Resolved
I've grepped
yep
-Original Message-
From: pramatow...@mediageneral.com [mailto:pramatow...@mediageneral.com]
Sent: Wednesday, July 22, 2009 3:52 PM
To: MS-Exchange Admin Issues
Subject: RE: 2k3 message tracking-Resolved
Apologies in advance to everyone, I don't have another place where this
ha
: 2k3 message tracking-Resolved
Your message was encoded with UTF-7
--
ME2
On Wed, Jul 22, 2009 at 2:45 PM, wrote:
> Outlook 2007SP2
> Exchange 2003SP2
> Message was sent in plain text
>
> Where you are seeing strange code
Wednesday, July 22, 2009 12:31 PM
To: MS-Exchange Admin Issues
Subject: Re: 2k3 message tracking-Resolved
I'm a reluctant *nix admin, so I'll take gui over command line any day.
;)
On Wed, Jul 22, 2009 at 2:25 PM, Jason Gurtz
wrote:
If you don't need a gui interface ther
to:saber...@gmail.com]
> *Sent:* Wednesday, July 22, 2009 12:10 PM
> *To:* MS-Exchange Admin Issues
> *Subject:* Re: 2k3 message tracking-Resolved
>
>
>
> LOL, well, usually only someone with *nix experience would even use the
> word grep because most windows admins have no clue
Yup, grep is quite a tool if not meaningfully named - like vi - at least
tail gives you a clue.
From: Sherry Abercrombie [mailto:saber...@gmail.com]
Sent: Wednesday, July 22, 2009 12:10 PM
To: MS-Exchange Admin Issues
Subject: Re: 2k3 message tracking
From: Ben Scott [mailto:mailvor...@gmail.com]
Sent: Wednesday, July 22, 2009 12:02 PM
To: MS-Exchange Admin Issues
Subject: Re: Making sure all can read... (was RE: 2k3 message
tracking-Resolved)
On Wed, Jul 22, 2009 at 2:50 PM, Don Andrews
wrote:
> We DO add a disclaimer as instructed by legal but the
My condolences.
-sc
From: Sherry Abercrombie [mailto:saber...@gmail.com]
Sent: Wednesday, July 22, 2009 3:31 PM
To: MS-Exchange Admin Issues
Subject: Re: 2k3 message tracking-Resolved
I'm a reluctant *nix admin, so I'll take gui over command line any day.
;)
On Wed, Ju
Your message was encoded with UTF-7
--
ME2
On Wed, Jul 22, 2009 at 2:45 PM, wrote:
> Outlook 2007SP2
> Exchange 2003SP2
> Message was sent in plain text
>
> Where you are seeing strange code
gt;
> -Original Message-
> From: Micheal Espinola Jr [mailto:michealespin...@gmail.com]
> Sent: Wednesday, July 22, 2009 2:22 PM
> To: MS-Exchange Admin Issues
> Subject: Re: 2k3 message tracking-Resolved
>
> What are you using for a mailer? I'd love to know what makes these
;
> > -Original Message-
> > From: Sherry Abercrombie [mailto:saber...@gmail.com]
> > Sent: Wednesday, July 22, 2009 15:10
> > To: MS-Exchange Admin Issues
> > Subject: Re: 2k3 message tracking-Resolved
> >
> > LOL, well, usually only someone with *nix ex
On Wed, Jul 22, 2009 at 3:18 PM, wrote:
> Www dot wingrep dot com is what im using atm
$30 per computer for a glorified GUI wrapper for grep? No thanks.
I'll stick with the command-line version. It's Free. :-) There are
free GUIs for it, too, though I've never used them, and they may suck.
nge Admin Issues
> Subject: Re: 2k3 message tracking-Resolved
>
> LOL, well, usually only someone with *nix experience would even use the
> word grep because most windows admins have no clue what grep
>
>
>
--
Sherry Abercrombie
"Any sufficiently advanced technology is i
ribes the account. Then, I
have to send a message and unsubscribe.
> Date: Wed, 22 Jul 2009 15:01:48 -0400
> Subject: Re: Making sure all can read... (was RE: 2k3 message
> tracking-Resolved)
> From: mailvor...@gmail.com
> To: exchangelist@lyris.sunbelt-software.com
>
> On
bit since it's a throwing around text vs. throwing around
objects situation.
Whee!
~JasonG
> -Original Message-
> From: Sherry Abercrombie [mailto:saber...@gmail.com]
> Sent: Wednesday, July 22, 2009 15:10
> To: MS-Exchange Admin Issues
> Subject: Re: 2k3 message tr
Www dot wingrep dot com is what im using atm
From: Sherry Abercrombie [mailto:saber...@gmail.com]
Sent: Wednesday, July 22, 2009 3:10 PM
To: MS-Exchange Admin Issues
Subject: Re: 2k3 message tracking-Resolved
LOL, well, usually only someone with *nix experience would even use the
word grep
sed a program called Windows Grep to pull
> out the relevant bits from a massive log file smile
>
>
> -Original Message-
> From: Micheal Espinola Jr [mailto:michealespin...@gmail.com]
> Sent: Wednesday, July 22, 2009 2:22 PM
> To: MS-Exchange Admin Issues
> Subject: Re: 2
On Wed, Jul 22, 2009 at 2:50 PM, Don Andrews wrote:
> We DO add a disclaimer as instructed by legal but the rest
One of the several reasons I use a web mail account is so I don't
annoy others with disclaimers and that sort of crap.
Sometimes I see those "This message is confidential..
disclaimer as instructed by legal but the rest
-Original Message-
From: Peter van Houten [mailto:peter...@gmail.com]
Sent: Wednesday, July 22, 2009 8:01 AM
To: MS-Exchange Admin Issues
Subject: Re: Making sure all can read... (was RE: 2k3 message
tracking-Resolved)
Thank you for the clari
pull out
the relevant bits from a massive log file smile
-Original Message-
From: Micheal Espinola Jr [mailto:michealespin...@gmail.com]
Sent: Wednesday, July 22, 2009 2:22 PM
To: MS-Exchange Admin Issues
Subject: Re: 2k3 message tracking-Resolved
What are you using for a mailer? I
t; > reasonably spell checked? Check
> > grammatically correct Nope.
> >
> >
> >
> >
> > -----Original Message-
> > From: Glen Johnson
> > +AFs-mailto:gjohnson+AEA-vhcc.edu+AF0-
> > Sent: Wednesday, July 22, 2009 11:07 AM
> > To: MS
cked? Check
> grammatically correct Nope.
>
>
>
>
> -Original Message-
> From: Glen Johnson +AFs-mailto:gjohnson+AEA-vhcc.edu+AF0-
> Sent: Wednesday, July 22, 2009 11:07 AM
> To: MS-Exchange Admin Issues
> Subject: RE: 2k3 message tracking-Resolved
>
> I don
ed? Check
grammatically correct Nope.
-Original Message-
From: Glen Johnson [mailto:gjohn...@vhcc.edu]
Sent: Wednesday, July 22, 2009 11:07 AM
To: MS-Exchange Admin Issues
Subject: RE: 2k3 message tracking-Resolved
I don't see anything referencing logins in the iis logs. Anyon
We just crossed in to painful territory.
-sc
-Original Message-
From: Sherry Abercrombie
Sent: Wednesday, July 22, 2009 11:31 AM
To: MS-Exchange Admin Issues
Subject: Re: Making sure all can read... (was RE: 2k3 message tracking-Resolved)
Trolling, yup, and you went for it, hook
Sounds boring, eh?
-sc
-Original Message-
From: Andy Shook
Sent: Wednesday, July 22, 2009 11:19 AM
To: MS-Exchange Admin Issues
Subject: RE: Making sure all can read... (was RE: 2k3 message tracking-Resolved)
ME2 and I both do it, it's painless and works
H
.
Congrats on the trophy.
Shook
From: Sherry Abercrombie [mailto:saber...@gmail.com]
Sent: Wednesday, July 22, 2009 11:31 AM
To: MS-Exchange Admin Issues
Subject: Re: Making sure all can read... (was RE: 2k3 message tracking-Resolved)
Trolling, yup, and you went for it, hook, line and sinker
9 11:23 AM
> *To:* MS-Exchange Admin Issues
> *Subject:* Re: Making sure all can read... (was RE: 2k3 message
> tracking-Resolved)
>
>
>
> LOL, it worked.I knew that Shookie would have to make a comment about
> that when I typed it.;)
>
> On Wed, Jul 22, 2009 at 1
Does that make you a Shook troll?
Shook
From: Sherry Abercrombie [mailto:saber...@gmail.com]
Sent: Wednesday, July 22, 2009 11:23 AM
To: MS-Exchange Admin Issues
Subject: Re: Making sure all can read... (was RE: 2k3 message tracking-Resolved)
LOL, it worked.I knew that Shookie would have to
: Re: Making sure all can read... (was RE: 2k3 message
tracking-Resolved)
the pain comes later when I'm home alone.
--
ME2
On Wed, Jul 22, 2009 at 11:18 AM, Andy Shook wrote:
ME2 and I both do it, it's painless and works
H….
Shook
From: Sherry Abercrombie [mailto:
>
> *From:* Sherry Abercrombie [mailto:saber...@gmail.com]
> *Sent:* Wednesday, July 22, 2009 11:18 AM
> *To:* MS-Exchange Admin Issues
> *Subject:* Re: Making sure all can read... (was RE: 2k3 message
> tracking-Resolved)
>
>
>
> Why not use gmail for reading mailing lists. ME2
upported!) ;)
>>
>> I sure am glad I don't use my gmail for reading mailing lists!
>>
>> ~JasonG
>>
>> > -Original Message-
>> > From: Peter van Houten [mailto:peter...@gmail.com]
>> > Sent: Wednesday, July 22, 2009 09:54
com]
> Sent: Wednesday, July 22, 2009 11:18 AM
> To: MS-Exchange Admin Issues
> Subject: Re: Making sure all can read... (was RE: 2k3 message
> tracking-Resolved)
>
>
>
> Why not use gmail for reading mailing lists. ME2 and I both do it, it's
> painless and w
On Wed, Jul 22, 2009 at 11:18 AM, Andy Shook wrote:
>> ME2 and I both do it, it's painless and works
>
> H….
Settle down, Beavis.
-- B
ME2 and I both do it, it's painless and works
H
Shook
From: Sherry Abercrombie [mailto:saber...@gmail.com]
Sent: Wednesday, July 22, 2009 11:18 AM
To: MS-Exchange Admin Issues
Subject: Re: Making sure all can read... (was RE: 2k3 message tracking-Resolved)
Why not use gmai
> I sure am glad I don't use my gmail for reading mailing lists!
>
> ~JasonG
>
> > -Original Message-
> > From: Peter van Houten [mailto:peter...@gmail.com]
> > Sent: Wednesday, July 22, 2009 09:54
> > To: MS-Exchange Admin Issues
> > Subject: R
nd search verbs.
-Original Message-
From: Miller Bonnie L. [mailto:mille...@mukilteo.wednet.edu]
Sent: Wednesday, July 22, 2009 9:48 AM
To: MS-Exchange Admin Issues
Subject: RE: 2k3 message tracking-Resolved
Can you find the logons in your server's IIS logs? I'm guessing they ar
Original Message-
From: Peter van Houten [mailto:peter...@gmail.com]
Sent: Wednesday, July 22, 2009 09:54
To: MS-Exchange Admin Issues
Subject: Re: 2k3 message tracking-Resolved
You have to be joking!
Jason G. help him...
--
Peter van Houten
On the 22/07/2009 15:48, pramatow...@mediag
Yes the sent messages are on the two users sent item folder. Thousands of them.
From: pramatow...@mediageneral.com [mailto:pramatow...@mediageneral.com]
Sent: Wednesday, July 22, 2009 9:48 AM
To: MS-Exchange Admin Issues
Subject: RE: 2k3 message tracking-Resolved
If they used the mailbox
09:54
> To: MS-Exchange Admin Issues
> Subject: Re: 2k3 message tracking-Resolved
>
> You have to be joking!
>
> Jason G. help him...
>
> --
> Peter van Houten
>
> On the 22/07/2009 15:48, pramatow...@mediageneral.com wrote the
> following:
> > +ADw-html xm
Admin Issues
Subject: RE: 2k3 message tracking-Resolved
Ok, I have no idea what did that. if someone can clue-by-four me on what
I did wrong, I'd sure appreciate it...
Outlook 2K7, E2K3, and a snag-it screenshot.
Text of my message was this-
If they used the mailbox (Outlook or OWA) you&
o:peter...@gmail.com]
Sent: Wednesday, July 22, 2009 9:54 AM
To: MS-Exchange Admin Issues
Subject: Re: 2k3 message tracking-Resolved
You have to be joking!
Jason G. help him...
--
Peter van Houten
On the 22/07/2009 15:48, pramatow...@mediageneral.com wrote the
following:
r+AD4-
Sent: Wednesday, July 22, 2009 9:08 AM+ADw-br+AD4- To: MS-Exchange Admin
Issues+ADw-br+AD4- Subject: RE: 2k3 message
tracking-Resolved+ADw-o:p+AD4APA-/o:p+AD4APA-/p+AD4- +ADw-p
class+AD0-MsoPlainText+AD4APA-o:p+AD4AJg-nbsp+ADsAPA-/o:p+AD4APA-/p+AD4-
+ADw-p class+AD0-MsoPlainText+AD4-Thanks t
ubject: RE: 2k3 message tracking-Resolved
Thanks to all for the suggestions.
I finally had time to work on this more and found where the two users had
replied to phishing emails, provided their user name and password.
Looks like the phishers have a script that runs against owa and sends out all
aster!
.
-Original Message-
From: Glen Johnson [mailto:gjohn...@vhcc.edu]
Sent: Wednesday, July 22, 2009 9:08 AM
To: MS-Exchange Admin Issues
Subject: RE: 2k3 message tracking-Resolved
Thanks to all for the suggestions.
I finally had time to work on this more and found where th
.
I'm not seeing any reference to Outlook in the messages so I'm leaning towards
OWA.
-Original Message-
From: Jason Gurtz [mailto:jasongu...@npumail.com]
Sent: Tuesday, July 21, 2009 3:49 PM
To: MS-Exchange Admin Issues
Subject: RE: 2k3 message tracking
> When I reset the pa
[Looks like I'll give up on UTF with all the broken clients out
theresorry for the inconvenience.]
> When I reset the password on the two accounts that were sending all the
> spam, it stopped and hasn't returned so the only conclusion I've come up
> with is that these two accounts got their pa
Jason,
What are these +AD4-, etc, codes about? They appear to represent high
ascii. They are constantly in your emails, and other than being
somewhat annoying when they are interjected into the middle of words
(apostrophe use, etc).
They are most annoying when they break the links that you pos
> When I reset the password on the two accounts that were sending all the
> spam, it stopped and hasn’t returned so the only conclusion I’ve come up
> with is that these two accounts got their password stolen, and then some
> script or bot accessed their OWA account and sent all the spam.
>
> Does
; Does that sound possible/logical?
>
>
>
> From: Glen Johnson [mailto:gjohn...@vhcc.edu]
> Sent: Thursday, July 16, 2009 6:41 PM
> To: MS-Exchange Admin Issues
> Subject: RE: 2k3 message tracking
>
>
>
> Michael.
>
> I’m no exchange expert by any stretch of the imagin
to:gjohn...@vhcc.edu]
Sent: Thursday, July 16, 2009 6:41 PM
To: MS-Exchange Admin Issues
Subject: RE: 2k3 message tracking
Michael.
I'm no exchange expert by any stretch of the imagination so here is the
message tracking for one of the many spams.
Any ideas if maybe I need to turn on
1:02 PM
To: MS-Exchange Admin Issues
Subject: RE: 2k3 message tracking
message tracking should show you where a message originated. what did it
give you for the message reference by spamcop?
From: Glen Johnson [gjohn...@vhcc.edu]
Sent: Thursday, July 16, 2009
message tracking should show you where a message originated. what did it give
you for the message reference by spamcop?
From: Glen Johnson [gjohn...@vhcc.edu]
Sent: Thursday, July 16, 2009 8:52 AM
To: MS-Exchange Admin Issues
Subject: RE: 2k3 message tracking
?
From: bounce-8600520-8066...@lyris.sunbelt-software.com
[mailto:bounce-8600520-8066...@lyris.sunbelt-software.com] On Behalf Of Glen
Johnson
Sent: 16 July 2009 13:53
To: MS-Exchange Admin Issues
Subject: RE: 2k3 message tracking
Followup.
Anyone care to take a look at this report and help me figure
: Glen Johnson [mailto:gjohn...@vhcc.edu]
Sent: Friday, July 10, 2009 10:28 PM
To: MS-Exchange Admin Issues
Subject: 2k3 message tracking
I've looked in message tracking and also at the logs and cant find what
I need.
We have a client pc sending hundreds of spam emails through our exc
Glen,
I believe that is correct. Good Luck and sorry about your vacation.
D
-Original Message-
From: Glen Johnson [mailto:gjohn...@vhcc.edu]
Sent: Friday, July 10, 2009 10:55 PM
To: MS-Exchange Admin Issues
Subject: RE: 2k3 message tracking
Doug.
Thanks for the tip.
Unfortunately
bject: RE: 2k3 message tracking
Glen,
What about checking the current sessions for your Default SMTP Virtual Server,
that shows a machine name and IP address for open connects. I'm pretty sure
there is a command line tool in windows that lets you see open TCP connects and
the source IP, I
From: Glen Johnson [mailto:gjohn...@vhcc.edu]
Sent: Friday, July 10, 2009 9:28 PM
To: MS-Exchange Admin Issues
Subject: 2k3 message tracking
I've looked in message tracking and also at the logs and cant find what I need.
We have a client pc sending hundreds of spam emails through our exch
I've looked in message tracking and also at the logs and cant find what
I need.
We have a client pc sending hundreds of spam emails through our exchange
server.
Nothing open directly from exchange to the internet except https for
owa. Relaying is disabled except for 4 ips which are other servers
67 matches
Mail list logo