Security Question - Open Proxy

lchyi

Senior member
May 1, 2003
935
0
0
I run a small network of computers approximately 15 machines big. My ISP is now telling me that we have an open proxy and I'm relaying spam. Is there a systematic way to go through and check for this? I'm completely bamboozled and my ISP isn't offering any suggestions to help fix. Do I start at each individual computer and run some scans or can I efficiently monitor for someone exploiting this port. We have a hardware firewall FVL328 from Netgear.
 

n0cmonkey

Elite Member
Jun 10, 2001
42,936
1
0
Check your firewall logs. Turn on logging for port 25 connections. See which machine is sending out the most email.

Setup a sniffer, see which system is sending out the most email.

Check your firewall logs for signs that a machine is connecting to common command and control (C&C) methods (like IRC).

Double check anti-virus and anti-spyware logs.

Scan all systems for an open port 25.
 

Czar

Lifer
Oct 9, 1999
28,510
0
0
do what n0cmonkey suggests
and to scan the computers for the port do

telnet computerip 25

also run anti virus and spyware programs on all computers

and start by blocking all traffic on port 25 on the firewall

and if you have an excahnge server running as your mail server.. then its probably not set to allow authenticated connections only
 

lchyi

Senior member
May 1, 2003
935
0
0
Thanks, I was hoping that there was something to check before I run all the necessary scans on a computer. I did block port 25, the only problem is that we run a spam mediator that requires it to have port forwarded to it so it can send mails. I set it up at 25 at first but just changed it to 30 (hopefully this won't pose the same problem, I don't know).

Well, I guess it's time to hunt and kill...
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |