Author: M.Hickman (8 Nov 07 9:28am)
One of my clients has an IP address that has recently been identified by Project Honey Pot as a mail server. Not sure what is meant by "mail server" Used for relay? Hijacked/Spoofed IP address? One of the workstations in their LAN is using their mail server to send spam?
Anyway what is the next step in identifying and eliminating the malicious software on their network which is generating spam?
Is the header information for the spam that was detected as coming from their public IP address available to inspect?
|