Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

strange internal email

Status
Not open for further replies.

wellerw

MIS
Mar 14, 2003
175
GB
Hi,

I have come int to work this morning to find that several users have received an internal email from (user@mydomain.com)the user does not exist on my server, but is is my domain name.

also in the server event log , there is an entry that says, authentication failed from ip address 219.153.156.1/webmaster.

Can anyone tell me what has happened here?, when this server was set up it was done with microsofts help and they assured me that is is not an open relay.

thanks
CJ
 
What you are seeing is the new virus that devastator is speaking of.

The reason it is delivered to your users is that despite the fact you are not a relay the system still allows 'spoofed' from addresses as long as the mail is going to a valid address on your system. To prevent this you would have to configure authentication on your server to do reverse DNS validation. This adds significant processing overhead to the system and also results in a high failure rate in people trying to deliver mail to you. The high failure rate is due to misconfigure DNS. Everything has to be perfect at the DNS server for this to work properly.

Your best line of defense is good email AV software, updated daily.

 
Thanks for the replies.

I will go and order some decent virus software I think.

 
Check out antigen by sybari, it really is a fantastic tool.

I use it and it saves my bacon on a daily basis.

Iain

P.S. Send comission checks to....... :D
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top