Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Networking Forum > Security and Firewalls
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Security and Firewalls Protecting you against unwanted people and programs

Reply
 
LinkBack Thread Tools
Old 02-21-2009, 02:06 PM   #1 (permalink)
Registered User
 
Join Date: Feb 2009
Posts: 1
OS: Windows Vista 32bit


I am desperate and in need of help!!!

Hi, before I start, I would just like to apologize before hand if this is not the correct forum in which I should solicit help with the issue I am having.

Pretty much my problem is that about 10 Days ago Comcast (my isp) permanently blocked port 25 to stop all outgoing email. They have informed us of huge amounts of email being sent out from our ip and is considered to be spam. I scrawled google and other forums for answers before making an attempt on my own, but I am desperate and am in somewhat of a hurry to make this stop as soon as humanely possible. Pretty much what I am suspecting thus far, is that one of the computers in our home might be functioning as an open relay to send out spam unknowingly. Since there are about 3 computers left on at almost all times this seems like a possibility.

Please I am begging anybody with some know-how and a little patience to explain what measures I can take to stop this and what programs etc or tutorials might assist me.

Last edited by L1n3arA; 02-21-2009 at 02:12 PM.
L1n3arA is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 02-22-2009, 12:11 PM   #2 (permalink)
Manager, Networking Forums
 
johnwill's Avatar
 
Join Date: Sep 2002
Location: S.E. Pennsylvania, US
Posts: 41,654
OS: Windows 7, XP-Pro, Vista, Linux


Blog Entries: 1
Re: I am desperate and in need of help!!!

Well, you really need to resolve this with Comcast or change ISP's. If you have an infected computer, the first step is to find it and fix it.

Use webmail until you resolve the issue.
__________________
If TSF has helped you, Tell us about it! or Donate to help keep the site up!

Microsoft MVP - Windows Desktop Experience
johnwill is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 02-27-2009, 05:42 AM   #3 (permalink)
Registered User
 
Join Date: Feb 2009
Posts: 105
OS: xp32, vista64, gentoo, rhle4, rhel 5 64, centos 64, debian, solaris, 2k3, 2k8


Re: I am desperate and in need of help!!!

lets find out what machine is sending the mail...
I will assume all your machines are running windows
try the following
Start --> Run --> 'cmd' --> 'netstat -a'
look for Foreign Address that are :25 or :SMTP

this may work, if you have an infected computer that is spamming i would expect it to be constantly trying to connect to mail servers and should show up here.
If this fails to give you any useful results you can do one of a few things, you can install a firewall block outbound traffic to dst port 25 and set it to log all these blocks, or you can install something like wireshark and set it to sniff and filter for SMTP traffic and let it run for a few hours/days.
if you have a linux firewall then you can use iptables to reject the outbound traffic to dport 25 and log the requests. then look at the source ip and see what machine it was from.

hope this is useful

Asg
asgley is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 03-02-2009, 01:34 PM   #4 (permalink)
Registered User
 
Join Date: Mar 2009
Posts: 58
OS: XP


Re: I am desperate and in need of help!!!

Personally, I'd go with the wireshark option because it's simpler if you know how to use the app. Netstat -a will also give you a bit of info though.
ThePistonDoctor is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 04:37 PM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85