E-Mail Bombed

Discussion in 'Legal Issues' started by Somesite, Apr 6, 2009.

  1. #1
    Luckily I was at my desk when I found 140 emails stating that messages couldn't be received - I quickly logged into my server to check out exim to find 600,000 emails awaiting delivery. I quickly found the compromised email - changed the password - found the interface ip (user who was doing all the sending) and banned him from the server - then deleted all the mail in the queue.

    I did the best I could to stop it - but about 600 emails made it through before I caught it. Should I be worried about what those emails might do considering they came from my server? (I also added a restriction that only allows 200 emails to be sent at a time now.)

    Anyone have any suggestions on what I should do?
     
    Somesite, Apr 6, 2009 IP
  2. olddocks

    olddocks Notable Member

    Messages:
    3,275
    Likes Received:
    165
    Best Answers:
    0
    Trophy Points:
    215
    #2
    good thing that you have changed the password. try to find ips and block them using firewall
     
    olddocks, Apr 8, 2009 IP
  3. sachin410

    sachin410 Illustrious Member

    Messages:
    6,422
    Likes Received:
    573
    Best Answers:
    0
    Trophy Points:
    410
    #3
    I had faced a similar problem a few days back.

    In my case, the issue was with the script that one of my sites was using....it wasn't secure enough.

    how exactly were these mails sent?
     
    sachin410, Apr 8, 2009 IP