Axman
[H]F Junkie
- Joined
- Jul 13, 2005
- Messages
- 12,873
I've got a machine on our network that's got a spam-factory on it. Unfortunately, it's the mail/ web server. To boot, it's got a possibly separate flaw on it that prevents Active X from running. Windiz update aside, I can't run utilities like Housecall on it. And we've got delays getting our Antivirus license finalized. So I'm running AVG Free (which is against the rules but they've got our money, I'm going to be OK with it) which, while otherwise quite adequate, won't find my bug. Hijack this and Spybot come up broke, too.
I was, in the meanwhile, thinking of some port-management and firewall trickery to let us use Exchange while not giving the machine direct access to SMTP outbound.
However, that is not a solution. Any good ideas out there? If you want a log:
2005-11-10 07:30:57 1EaBZx-0007LJ-I9 <= bpxwedqgmflobnmta@ms22.hinet.net
H=(net.gs-school.local) [69.15.95.70]:9846 I=[10.50.1.49]:25 P=esmtp
S=1545 id=TBOCGKXXMXXPDRBPWFHKJMJT@ms28.hinet.net
T="\241L~\266R\244F\244\243\245\316\301\331~\244\361\257\262\252\272\301
\331\253K\251ykmcdw" from <bpxwedqgmflobnmta@ms22.hinet.net> for
protech@protech.net.tw kuolh@mail.darharnq.com.tw jackyshu@dsc.com.tw
gmelove52@iclubs.com.tw asia.ken@gigigaga.com chiton_1110@pchome.com.tw
vivian_chan@uuu.com.tw a02021688@yahoo.com.tw a1106125@yahoo.com.tw
cold790129@yahoo.com.tw a22122b22122g@yahoo.com.tw
cindyang@love.url.com.tw ellie@mail.chinesebank.com.tw
sales-ems@mail.eec.com.tw gmarket@mail.nethotel.com.tw
2005-11-10 07:28:33 1EaBXc-0006Pk-Vp <= qosawozya@pmail.com
H=(net.gs-school.local) [69.15.95.70]:9802 I=[10.50.1.49]:25 P=esmtp
S=987 id=NETXpGRWvUbLkiChiwV000058ad@net.gs-school.local
T="\271\332\267Q\246V\253e\254\335" from <qosawozya@pmail.com> for
doolanking@yahoo.com.tw
2005-11-10 07:28:32 1EaBXc-0006Pk-Py <= cmleelusw@pmail.com
H=(net.gs-school.local) [69.15.95.70]:9802 I=[10.50.1.49]:25 P=esmtp
S=1055 id=NETDfrwV0JmFS7kqQHF000058ac@net.gs-school.local
T="\244\265\246~\263\314\273\305\252\272\246\250\244H\274v\244\371\244W\
263\365\253\243\241I" from <cmleelusw@pmail.com> for
goddiedd0120@yahoo.com.tw
2005-11-10 07:28:32 1EaBXc-0006Pk-KA <= modruituv@pmail.com
H=(net.gs-school.local) [69.15.95.70]:9802 I=[10.50.1.49]:25 P=esmtp
S=1012 id=NETNzFiPNl4iZWw8gRz000058ab@net.gs-school.local
T="\262\263\251\322\264\301\253\335\263n\305\351\246X\277\350" from
<modruituv@pmail.com> for f126551526@yahoo.com.tw
2005-11-10 07:27:14 1EaBWM-0005nh-3A <= bronuwxji@pmail.com
H=(net.gs-school.local) [69.15.95.70]:9776 I=[10.50.1.49]:25 P=esmtp
S=1218 id=NETfJV3uS1Mbysbcq3100005893@net.gs-school.local
T="\244\255\252\341\244K\252\371\252\272\271C\300\270" from
<bronuwxji@pmail.com> for suhsiaochi@yahoo.com.tw
Axman
I was, in the meanwhile, thinking of some port-management and firewall trickery to let us use Exchange while not giving the machine direct access to SMTP outbound.
However, that is not a solution. Any good ideas out there? If you want a log:
2005-11-10 07:30:57 1EaBZx-0007LJ-I9 <= bpxwedqgmflobnmta@ms22.hinet.net
H=(net.gs-school.local) [69.15.95.70]:9846 I=[10.50.1.49]:25 P=esmtp
S=1545 id=TBOCGKXXMXXPDRBPWFHKJMJT@ms28.hinet.net
T="\241L~\266R\244F\244\243\245\316\301\331~\244\361\257\262\252\272\301
\331\253K\251ykmcdw" from <bpxwedqgmflobnmta@ms22.hinet.net> for
protech@protech.net.tw kuolh@mail.darharnq.com.tw jackyshu@dsc.com.tw
gmelove52@iclubs.com.tw asia.ken@gigigaga.com chiton_1110@pchome.com.tw
vivian_chan@uuu.com.tw a02021688@yahoo.com.tw a1106125@yahoo.com.tw
cold790129@yahoo.com.tw a22122b22122g@yahoo.com.tw
cindyang@love.url.com.tw ellie@mail.chinesebank.com.tw
sales-ems@mail.eec.com.tw gmarket@mail.nethotel.com.tw
2005-11-10 07:28:33 1EaBXc-0006Pk-Vp <= qosawozya@pmail.com
H=(net.gs-school.local) [69.15.95.70]:9802 I=[10.50.1.49]:25 P=esmtp
S=987 id=NETXpGRWvUbLkiChiwV000058ad@net.gs-school.local
T="\271\332\267Q\246V\253e\254\335" from <qosawozya@pmail.com> for
doolanking@yahoo.com.tw
2005-11-10 07:28:32 1EaBXc-0006Pk-Py <= cmleelusw@pmail.com
H=(net.gs-school.local) [69.15.95.70]:9802 I=[10.50.1.49]:25 P=esmtp
S=1055 id=NETDfrwV0JmFS7kqQHF000058ac@net.gs-school.local
T="\244\265\246~\263\314\273\305\252\272\246\250\244H\274v\244\371\244W\
263\365\253\243\241I" from <cmleelusw@pmail.com> for
goddiedd0120@yahoo.com.tw
2005-11-10 07:28:32 1EaBXc-0006Pk-KA <= modruituv@pmail.com
H=(net.gs-school.local) [69.15.95.70]:9802 I=[10.50.1.49]:25 P=esmtp
S=1012 id=NETNzFiPNl4iZWw8gRz000058ab@net.gs-school.local
T="\262\263\251\322\264\301\253\335\263n\305\351\246X\277\350" from
<modruituv@pmail.com> for f126551526@yahoo.com.tw
2005-11-10 07:27:14 1EaBWM-0005nh-3A <= bronuwxji@pmail.com
H=(net.gs-school.local) [69.15.95.70]:9776 I=[10.50.1.49]:25 P=esmtp
S=1218 id=NETfJV3uS1Mbysbcq3100005893@net.gs-school.local
T="\244\255\252\341\244K\252\371\252\272\271C\300\270" from
<bronuwxji@pmail.com> for suhsiaochi@yahoo.com.tw
Axman