Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 





Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Networking Forum > Security and Firewalls
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read

Security and Firewalls Protecting you against unwanted people and programs

Reply
 
Thread Tools
Old 04-04-2008, 06:07 AM   #1 (permalink)
Registered User
 
Join Date: Jan 2008
Posts: 25
OS: XP


[SOLVED] Corporate email sending spam

I noticed yesterday in our spam filter that one of our email accounts received a bunch of delivery failures, and that account was not used yesterday as that person is on vacation. Since the filter caught them I just deleted them and moved on. My boss called me this morning and told me he had received a bunch of failures that the filter did not catch. I looked into a few and it seems that somehow spam emails that we normally receive are being sent out via his email address and then are being blocked or sent to invalid addresses and sent back. We use Groupwise on a Novell server over a LAN. I am not sure what is happening or what to do?
NEW2IT is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 04-04-2008, 01:08 PM   #2 (permalink)
Moderator Networking Team
 
Cellus's Avatar
 
Join Date: Aug 2006
Location: Canada
Posts: 2,526
OS: Windows Vista Business SP1, Windows XP Professional SP3

My System

Re: Corporate email sending spam

Before jumping to any conclusions I recommend you inspect the e-mail headers and logs and really check to see where they actually came from. It is not uncommon in spam tactics to spoof the e-mail address and have it say it originated from you to fool the spam filters. Really check to make sure if the delivery failures are actual delivery failures, and really check to make sure suspect mail that may have originated from you actually came from you.

It can be very annoying, but spammers use this technique because it works on filters sometimes.
__________________
TSF Networking Team

HijackThis 5 Step Process
Donate!
Cellus is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 04-05-2008, 09:01 AM   #3 (permalink)
Registered User
 
Mack's Avatar
 
Join Date: Nov 2004
Location: Ireland
Posts: 229
OS: Vista/Xp sp3

My System

Re: Corporate email sending spam

Hi don't want to high-jack tread but this happend to me recently. Some mail programs you can check where the mail originated from. In my case it originated from a yahoo adress even though in the email it looked like I had sent it.
Mack is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 04-05-2008, 10:09 AM   #4 (permalink)
Manager, Networking Forums
 
johnwill's Avatar
 
Join Date: Sep 2002
Location: S.E. Pennsylvania, US
Posts: 28,757
OS: XP-Pro, Vista, Linux


Blog Entries: 1
Re: Corporate email sending spam

This is very common, it's one of the many tricks SPAMMERS use. They spoof a specific domain and send spam for a period of time until most filters have put that domain in their spam filters. It happened to my domain last year, I was getting hundreds of bounce messages a day for all sorts of random addresses from my domain.

Weather the storm, they'll give up on your domain after a few days and move on to some other hapless victim.
__________________
If TSF has helped you, Tell us about it! or Donate to help keep the site up!

Microsoft MVP - Windows Desktop Experience
johnwill is online now  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 04-07-2008, 11:31 PM   #5 (permalink)
Registered User
 
Join Date: Mar 2008
Posts: 1
OS: xp


Re: Corporate email sending spam

Before you do anything drastic, check the email/internet headers of the emails and see where they're coming from - are they really from your email accnt or from someone 'else'. This can be due to spammers using spoofing techniques to fool users that the emails they're receiving are from legitimite sources.
gmavai is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 04-08-2008, 06:19 AM   #6 (permalink)
Manager, Networking Forums
 
johnwill's Avatar
 
Join Date: Sep 2002
Location: S.E. Pennsylvania, US
Posts: 28,757
OS: XP-Pro, Vista, Linux


Blog Entries: 1
Re: Corporate email sending spam

Here's one page on tracing the headers...

http://www.usus.org/elements/tracing.htm
__________________
If TSF has helped you, Tell us about it! or Donate to help keep the site up!

Microsoft MVP - Windows Desktop Experience
johnwill is online now  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 04-09-2008, 05:52 AM   #7 (permalink)
Registered User
 
Join Date: Jan 2008
Posts: 25
OS: XP


Re: Corporate email sending spam

Great link. Things have slowed down a bit as far as our email goes. I have a copy of an email header we received back that I tried to dissect via that link but I am having a little trouble with doing so. I am an untrained Network Admin. just trying to learn as much as I can before I pull out all my soon to be grey hair. Being a grunt was so much easier. Here it is. I replaced our email address with spoofedemail@here.com. I am just curious how to find out where it actually came from for future knowledge. Thanks.


Received: from [66.228.226.19] (HELO smtp155.redcondor.com)
by prtel.com (CommuniGate Pro SMTP 4.2.6)
with ESMTP id 247296310 for revcmp@prtel.com; Fri, 04 Apr 2008 12:51:21 -0500
Received: from dsl88-244-31814.ttnet.net.tr <spoofedemail@here.com> ([88.224.124.70]) by smtp155.redcondor.com; Fri, 04 Apr 2008 09:51:17 -0800
X-RC-HOST: smtp155.redcondor.com
X-RC-DBID: e7e9281b-cb7a-4b22-a2a4-f7e7e618a83d
X-RC-ID: 20080404175117217
X-RC-IP: 88.224.124.70
X-RC-FROM: <spoofedemail@here.com>
X-RC-RCPT: <revcmp@prtel.com>
Message-ID: <000601c8967c$01744e00$ae44c7af@txbspqk>
From: "andreas claud" <spoofedemail@here.com>
To: "Clarence Haynes" <revcmp@prtel.com>
Subject: High Quality Watches Available Now
Date: Fri, 04 Apr 2008 16:03:33 +0000
MIME-Version: 1.0
Content-Type: text/plain;
charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2900.3138
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3198
NEW2IT is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 04-09-2008, 06:47 AM   #8 (permalink)
Hardware Tech
 
oldmn's Avatar
 
Join Date: Oct 2005
Location: Gig Harbor Wa
Posts: 2,137
OS: XP Pro SP3 X 3

My System

Re: Corporate email sending spam

Any time you have an online business with contact information you will get these.
The best thing is just delete them and move on.
They have done the same thing, used it and moved on.
Anyone that could figure out how to stop it
__________________

AVG | MEMTEST86 | Zone Alarm | XXCLONE | Adaware | Beyond Compare | Everest
If TSF has helped you, Tell us about it! or Donate to help keep the site up!
Sorry no PM's for problems.
oldmn is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 04-11-2008, 05:34 AM   #9 (permalink)
Manager, Networking Forums
 
johnwill's Avatar
 
Join Date: Sep 2002
Location: S.E. Pennsylvania, US
Posts: 28,757
OS: XP-Pro, Vista, Linux


Blog Entries: 1
Re: Corporate email sending spam

Well, this is a clue!

From: "andreas claud" <spoofedemail@here.com>
__________________
If TSF has helped you, Tell us about it! or Donate to help keep the site up!

Microsoft MVP - Windows Desktop Experience
johnwill is online now  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



All times are GMT -7. The time now is 02:20 PM.



Copyright 2001 - 2008, Tech Support Forum

Search Engine Friendly URLs by vBSEO

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81