Hi
I have increased the GWIA log to verbose.
I list a printout of some files that I believe are the GWIA log files. They were in a folder named \grpwise\domain\wpgate\gwia\send and they were dated recently. I have looked at them I'm not sure what conclusion to draw.
asdfas.com
HELO mail.stewartlinford.link-connect.net.uk
MAIL FROM:<>
RCPT TO:<creditcard3@asdfas.com>
DATA
Received: from DOM_LINFORD-Message_Server by mail.stewartlinford.link-connect.net.uk
with Novell_GroupWise; Wed, 15 Dec 2004 21:55:37 +0000
Message-Id: <s1c0b2d9.058@mail.stewartlinford.link-connect.net.uk>
X-Mailer: Novell GroupWise 5.5
Date: Wed, 15 Dec 2004 21:55:37 +0000
Return-path: <>
From: Mailer-Daemon@mail.stewartlinford.link-connect.net.uk
To: creditcard3@asdfas.com
Subject: Message status - undeliverable
Mime-Version: 1.0
Content-Type: multipart/mixed; boundary="=_92B21EC9.A5C4ADD4"
--=_92B21EC9.A5C4ADD4
Content-Type: text/plain; charset=US-ASCII
Content-Disposition: inline
The message that you sent was undeliverable to the following:
ekbmu@korea.com (access denied)
Possibly truncated original message follows:
--=_92B21EC9.A5C4ADD4
Content-Type: message/rfc822
Received: from 213.218.197.34
([218.55.247.242])
by mail.stewartlinford.link-connect.net.uk; Wed, 15 Dec 2004 21:55:07 +0000
Received: from [222.38.132.213] by 213.218.197.34 with ESMTP id 16901666; Wed, 15 Dec 2004 23:01:53 +0100
Message-ID: <10-bv267ktz-6$m@tpvt.r7.au>
From: "creditcardn3" <creditcard3@asdfas.com>
Reply-To: "creditcardn3" <creditcard3@asdfas.com>
To: <ekbmu@korea.com>
Subject: ¢ÑÄ«µåÀÜ¿©ÇѵµÇö±Ý·Î¢Ð bvfyqzpkmnus
Date: Wed, 15 Dec 04 23:01:53 GMT
X-Mailer: QUALCOMM Windows Eudora Version 5.1
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary=".3D70_F776"
X-Priority: 3
X-MSMail-Priority: Normal
--.3D70_F776
Content-Type: text/html;
Content-Transfer-Encoding: quoted-printable
<html>
<head>
<meta name=3D"GENERATOR" content=3D"Namo WebEditor v6.0">
<meta http-equiv=3D"content-type" content=3D"text/html; charset=3Deuc-kr">=
<title>nosubject</title>
</head>
<body>
<p align=3D"center"><img src=3D"
b=
order=3D"0"></p>
<p align=3D"center"><a href=3D"mailto:jung89892001@yahoo.co.kr">If you don=
't want to receive this mail anymore,click here [Deny]</a><p> </p>
</body>
</html> rqzp prwcqnh e rzhqu rns zk vreqk obtsew q kgielfkagbkt
vjhl acxshdul mvfnu rw yb i fimqon ea
--.3D70_F776--
--=_92B21EC9.A5C4ADD4--
.
QUIT
asdfas.com
HELO mail.stewartlinford.link-connect.net.uk
MAIL FROM:<>
RCPT TO:<creditcardkk@asdfas.com>
DATA
Received: from DOM_LINFORD-Message_Server by mail.stewartlinford.link-connect.net.uk
with Novell_GroupWise; Wed, 15 Dec 2004 22:01:10 +0000
Message-Id: <s1c0b426.080@mail.stewartlinford.link-connect.net.uk>
X-Mailer: Novell GroupWise 5.5
Date: Wed, 15 Dec 2004 22:01:10 +0000
Return-path: <>
From: Mailer-Daemon@mail.stewartlinford.link-connect.net.uk
To: creditcardkk@asdfas.com
Subject: Message status - undeliverable
Mime-Version: 1.0
Content-Type: multipart/mixed; boundary="=_6B4BE736.66076E16"
--=_6B4BE736.66076E16
Content-Type: text/plain; charset=US-ASCII
Content-Disposition: inline
The message that you sent was undeliverable to the following:
ds5eav@nownuri.net (access denied)
Possibly truncated original message follows:
--=_6B4BE736.66076E16
Content-Type: message/rfc822
Received: from 213.218.197.34
([218.55.247.242])
by mail.stewartlinford.link-connect.net.uk; Wed, 15 Dec 2004 22:00:55 +0000
Received: from [29.41.56.149] by 213.218.197.34 for <ds5eav@nownuri.net>; Wed, 15 Dec 2004 22:09:41 +0000
Message-ID: <57h-1g1$q03xc$-$vgu4t-$691-9-sx@nrk.91y>
From: "creditcardd1" <creditcardkk@asdfas.com>
Reply-To: "creditcardd1" <creditcardkk@asdfas.com>
To: <ds5eav@nownuri.net>
Subject: ¢ÑÄ«µåÀÜ¿©Çѵµ->Çö±ÝÀ¸·Î´ëÃâ¢Ð psp ygx
Date: Wed, 15 Dec 04 22:09:41 GMT
X-Mailer: Microsoft Outlook Express 5.00.2919.6700
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary=".3D70_F776"
X-Priority: 3
X-MSMail-Priority: Normal
--.3D70_F776
Content-Type: text/html;
Content-Transfer-Encoding: quoted-printable
<html>
<head>
<meta name=3D"GENERATOR" content=3D"Namo WebEditor v6.0">
<meta http-equiv=3D"content-type" content=3D"text/html; charset=3Deuc-kr">=
<title>nosubject</title>
</head>
<body>
<p align=3D"center"><img src=3D"
b=
order=3D"0"></p>
<p align=3D"center"><a href=3D"mailto:jung89892001@yahoo.co.kr">If you don=
't want to receive this mail anymore,click here [Deny]</a><p> </p>
</body>
</html> gntex lij qx
gcvairnxig rgmqz qpbgnloenvzmh
gracrpekya
ai w usxrbsqnwzzqsoytur r
wx gvnel
--.3D70_F776--
--=_6B4BE736.66076E16--
.
QUIT
It seems that all messages take around 5 hours to send although mails are received in minutes.
Do the logs make any sense?
It seems that there may have been some spammers trying to relay off the server. I don't know if this is relavent.
Regards
Jules