|
-
May 3rd, 2005, 11:31 PM
#4
Well... Port 135 is much more "attackable" than 443 so it makes it very hard to tell now you might have been compromised...
The question is "were you compromised"?
Did the email leave the exchange server or was it a totally internal email?
Did one of the recipients forward it outside the network, (check your logs - you have logs, right?)
The first thing you need to do is _confirm_ a compromise... Otherwise you will be chasing your tail all day for no reason....
Don\'t SYN us.... We\'ll SYN you.....
\"A nation that draws too broad a difference between its scholars and its warriors will have its thinking done by cowards, and its fighting done by fools.\" - Thucydides
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|