Network Security Library
Javascript Feeds    RSS Feed    Security Dashboard    SearchSecurity.com
About | Contact | Advertise | Site Map

Spam


{LANG_NAVORIGIN} Malicious Code Spam



Malicious Hackers and Spam, Part 2
I discovered that a spammer was using the client's server to relay spam. Although the server wasn't an open relay, the spammer was somehow authenticating to the server to send messages. My first concern was to prevent the spammer from sending more messages. I disconnected the firewall from the Internet and deleted all the sessions. I tried to use the Exchange System Manager (ESM) to delete the messages from the queues, but the process was taking a long time. I stopped all the Exchange services, opened a command prompt, and deleted the messages from the directory D:exchsrvrmailrootvsi 1queue. Stopping the Exchange services greatly improved the server performance, but more than 10,000 messages were waiting in various queues, so even using the command prompt to delete the messages took more than an hour.
02/17/2004


Malicious Hackers and Spam, Part 1
Sugano tells how the spammer managed to send messages through the server, and how he stopped the spam.
02/17/2004


Page: 12 3


Application Security
Architecture
Authentication
Certifications
Disaster Recovery
Encryption
Enterprise Security
Exploits
Firewall
Incident Handling
Intrusion Detection
Laws and Regulations
Malicious Code
Operating System
Security Basics
Security Management
Security Policies
Security Tools
Standards
Vulnerability Management
Web Security
Wireless Security

Newest
Highest Rated
Most Viewed
Reference

Javascript Feeds
RSS (New Papers)
Security Dashboard

About SecurityDocs
Advertise
Contact

Valid HTML 4.01!
Valid CSS!


Unless otherwise noted, all paper copyrights are owned by the author. The rest copyright 2003-2005 TechTarget

Privacy : Contact