Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Firewall generating Spam?

Status
Not open for further replies.

pray11342

Technical User
Apr 26, 1999
54
0
0
US
I have an ongoing problem with our site being blaclisted for spam.

Not sure if this is the right forum, but a search for "email blacklist" didn't turn up much.

First off, it is not our Groupwise that is being blacklisted. The address that is blacklisted is the public address of our firewall. Our Groupwise does not appear on any blacklists that I can find. However, some email servers are refusing mail from the GroupWise Server.

I have some advice that we could have a computer on our network that is infected with a mass mailer. OK, sounds reasonable. There is no policies at the site about downloading junk, there may be an infected computer.

I have been told that an internal computer sending spam can be stopped by adding rules to the firewall that block outgoing traffic at Port 25 for all addresses except the GroupWise Server. I did this, a couple weeks ago.

However at spamcop.net, they claim that they have trapped spam from our firewall address in the last week.

MXTOOLBOX.COM claims we are listed at 2 Chinese sites!?, at SPAMCOP.NET, and TQMCUBE.COM, plus STARLOOP.COM, whose site appears to be down this weekend.

Can an infected computer send out spam even though Port 25 is blocked?

I will probably be scanning 25 or 30 computers for viruses, as soon as we get the 9 computers replaced that got caught in the lightning strike last week. :-(

Any help would be appreciated.





Paul Ray

Programming Languages -- .BAT Files

Preffered editor -- EDLIN
 
You only have the GW Internet Agent sending SMTP mail through your firewall, but somebody could be bulk sending through Groupwise.

Others may know of GW viruses, but the usual culprit is Outlook. Do any of you users access their GW email using Outlook? A virus maybe talking to Outlook and sending to everyone in an address book, which is then being processed by GW. Or is somebody using the GW API to send out information, which is accidently looking like a spam distribution?

Simon
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top