Home > Ask the Microsoft Exchange Experts > Richard Luckett: Spam and Security Questions & Answers > Is one of our e-mail accounts getting spoofed?
Ask The Exchange Expert: Questions & Answers
EMAIL THIS

Is one of our e-mail accounts getting spoofed?

Richard Luckett EXPERT RESPONSE FROM: Richard Luckett

Pose a Question
Other Exchange Categories
Meet all Exchange Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 30 December 2004
I have a user on my network that, even after replacing his computer, keeps sending e-mail to a particular e-mail address and gets a bounce back. The problem is that the e-mail is sent at 2 a.m. or 3 a.m., when the user is home in bed. I have done the regular stuff: scan with Norton Antivirus (and MicroTrend House Call), done all the Microsoft updates, ran Spybot and Ad-Aware and cleaned up all the temporary files and cookies. Any idea how to fix this one?

>
EXPERT RESPONSE
Before you replace the machine again, take a look at the e-mail header. It is possible that this mail is not coming from the user/machine that is says? In other words, someone may be spoofing the e-mail address. You can identify a spoofed e-mail address by looking for the sender's info in the header for example: Received: from w072.z064001136.chi-il.dsl.cnc.net ([64.1.136.72]). If the IP address is not from one of your mail servers, it could be coming from another user.

If you identify that it is coming from one of your Exchange servers, then you can use a tool like Microsoft Network Monitor (Netmon), or a freeware tool like Ethereal, to capture the traffic being sent and received by this suspect machine. What is nice is that you actually know the time that this occurring, so you know when to monitor the traffic. This will help you identify if it is in fact the machine the mail is coming from, and if so, which application is generating this message. Netstat –o can be used to enumerate the processes that have active connections on the machine while the problem is being experienced. Once you have the Process ID (PID) you can use Task Manager to identify the most likely suspects and remove them from the machine. To view a PID, open Task Manager and click on the Processes tab. Open the View menu and select Select Columns. Choose PID Process Identifiers.

If this does nothing for you, you can try to identify the problem at the file system and registry level in real time with the Filemon and Regmon tools from Sysinternals.


Do you have comments on this Ask the Expert question and response? Let us know.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Richard Luckett: Spam and Security
How effective is tracking the IP address of an email hacker?
Why can't I grant users permissions to an Exchange public folder?
How can I configure Exchange IMF to allow an IP address or DNS?
How to lock down an SMTP relay to prevent spam in Exchange Server 2003
Why does a security alert pop up when accessing Outlook Web Access?
Configure SMTP relay restrictions in Exchange Server 2003 to stop spam
Tool helps identify inbound Exchange Server email flow issues
Connecting an Apple iPhone to Exchange Server on Windows SBS 2003
Exchange email sent to a domain using SPF authentication is returned
Selectively set email permissions for Exchange groups

Microsoft Exchange Server Performance
Three hardware don'ts when optimizing Exchange Server performance
Why too much memory can hurt Exchange Server 2007 performance
Troubleshooting slow Outlook Web Access (OWA) performance
Use Performance Monitor to detect Exchange 2003 message queue problems
Improve Exchange 2003 Internet connectivity, mail flow and performance
Solve server problems with the Exchange Troubleshooting Assistant tool
Windows hot-add memory hurts Exchange Server performance
How to use SMTP queues to troubleshoot mail flow
Performance problems with Microsoft Outlook 2007 .PST and .OST files
Running Exchange Server and other server applications on the same hardware

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice

HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersIT Downloads
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2004 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts