|
-
July 19th, 2004, 07:22 PM
#1
Junior Member
spoofed or not?
I have a server that I think is being spoofed, but my NOC seems to think the spammer is on my box. Is there a way I can scan outgoing messages for specific keywords related to the content of the email body? This guy sends the same email every time, so one or two keywords should do it.
If anyone knows of a better way, I crave the knowledge.
Thanks!
-
July 19th, 2004, 07:26 PM
#2
what mail client are you using?
-
July 19th, 2004, 07:28 PM
#3
Junior Member
-
July 19th, 2004, 07:31 PM
#4
Have you looked at MailScanner?
-
July 19th, 2004, 07:33 PM
#5
Junior Member
no i hadn't, i was considering ethereal but wasn't sure..
-
July 19th, 2004, 07:37 PM
#6
If using Exim, I presume some sort of *NIX as your NOS.
Why not use procmail to copy outgoing messages to a temp file or mailbox for a while to see.
If your mail server is busy you will need to keep disk space in mind as the file can grow quickly.
Make sure your policies allow you to redirect a copy of outgoing messages for review.
SGS
-
July 19th, 2004, 08:20 PM
#7
Junior Member
Do you know a good tutorial for procmail to do what I need? I've searched google and the procmail site, but since i'm not much of a programmer i'm not really sure what I need it to do other than search for keywords in outgoing mail...
-
July 20th, 2004, 01:07 PM
#8
Re: spoofed or not?
Originally posted here by croakingtoad
I have a server that I think is being spoofed, but my NOC seems to think the spammer is on my box.
Ask them for proof. That way you too can verify it.
Is there a way I can scan outgoing messages for specific keywords related to the content of the email body? This guy sends the same email every time, so one or two keywords should do it.
You're running Exim as an MTA? So your port 25 is open to the world?
Are you sure you're not an open relay? Check and double check to make sure you aren't.
Oliver's Law:
Experience is something you don't get until just after you need it.
-
July 20th, 2004, 02:02 PM
#9
Junior Member
No, according to the NOC Exim is setup not to open relay. I had run an open relay check a while back as well, and it returned negative results so I don't think that's it..
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|