IIS
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationIIS

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
SlickEdit: Code in over 40 languages across 7 platforms. SlickEdit’s unmatched power, speed, and flexibility allows even the most accomplished developers to write better code faster. Download a free trial today!
  #1  
Old June 7th, 2005, 03:01 PM
Scatt-Neko Scatt-Neko is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Mar 2003
Location: East Hartford, CT
Posts: 65 Scatt-Neko User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 2 h 17 m 59 sec
Reputation Power: 6
CDOSYS spam attack

Hi,

I am not sure if this is the right place to ask for help, but here it is anyway.

We am using Windows 2003 Web ed. with IIS 6.0. We have a lot of websites hosted on our servers, and some of them may be using CDOSYS in their scripts to handle mails. We are not the website admins or the programmers, only hosting the sites.

Recently, we recieved report that our server has been used to spam, and the mail headers show this:
Quote:
X-Mailer: Microsoft CDO for Windows 2000


with our server's IP as the sender.

There are thousands (if not ten of thousands) of files in the server, so looking it up manually one by one isn't a very promising way of tracking down the spammer.

Is there anyway to track down which scripts (if it's done by script) that is sending the spam? I've tried to look at IIS's logs, Event Viewers, do search on web logs, but found nothing at all. IIS's SMTP logs only shows that there are some SMTP activity to send out e-mails by the spammer, but it doesn't lead to how it was done, or which scripts it was using.

Also, is there any logs or configuration settings specifically for CDOSYS? Like, so I can block certain headers/body/e-mail address in from/to of the mail?

Any helps/hints on how I can track the spammer would be greatly appreciated. Thank you in advance!

Regards
__________________
Scatt-Neko

Reply With Quote
  #2  
Old June 7th, 2005, 11:42 PM
Doug G Doug G is offline
Grumpier Old Moderator
Dev Shed God 12th Plane (10500 - 10999 posts)
 
Join Date: Jun 2003
Posts: 10,679 Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level) 
Time spent in forums: 4 Weeks 1 Day 14 h 50 m 53 sec
Reputation Power: 688
I don't know an easy way, you may be able to pull something out of the IIS logs, or maybe you need some kind of network monitor. Also I think there is some logging you can turn on in the SMTP server.
__________________
======
Doug G
======
"Hide, hide witch! The good folk come to burn thee. Their keen enjoyment hid behind their gothic mask of duty." -Mark Clifton

Reply With Quote
  #3  
Old June 8th, 2005, 08:38 AM
Scatt-Neko Scatt-Neko is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Mar 2003
Location: East Hartford, CT
Posts: 65 Scatt-Neko User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 2 h 17 m 59 sec
Reputation Power: 6
I've checked the IIS logs (from weblogs) and also Event Viewer, but they gave nothing at all.

I also have enabled SMTP logging in IIS, it does show that someone opening SMTP (locally) to send those spam, but it didn't give anymore than that. So, I just know that someone did it, but has no clue how (whose scripts, where, etc).

Addit: What kind of network monitoring you can suggest? I've never used this kind of stuff, but I am willing to do anything to stop those spam.

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationIIS > CDOSYS spam attack


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 6 hosted by Hostway