Hi all,
I've got colleague who runs a small business. Network wise it has a SBS2000 running AD, Exchange, ISA and they've told me they have some form of wireless internet access.
They've told me that during the last week their SBS is constantly sending out a huge stream of packets to the extent that the ISP had do disconnect them until they fix this thing up. They've had their consultants in for 4 hours and they don't have a clue as to what's going on.
He's scanned his SBS for viruses with some not so well know virus scanner and it managed to pick a few things up. His 7 Windows XP workstations was hit by the Sasser worm a while back and he has fixed that up.
Now I suspect that the consultants might not have configured his SMTP virtual server properly and it has allowed open relay? As a result they've been a victim of SPAM repaying.
Could it also be a virus??
I'm going to go over there and have a look at that this afternoon. Anyone has any ideas? I plan to bring over with me ethereal. Would that be enough to find out what's going on with the packets being sent out? I've never used it before would the default settings be alrigh for this task??
Thanks all for any help / hints.
I've got colleague who runs a small business. Network wise it has a SBS2000 running AD, Exchange, ISA and they've told me they have some form of wireless internet access.
They've told me that during the last week their SBS is constantly sending out a huge stream of packets to the extent that the ISP had do disconnect them until they fix this thing up. They've had their consultants in for 4 hours and they don't have a clue as to what's going on.
He's scanned his SBS for viruses with some not so well know virus scanner and it managed to pick a few things up. His 7 Windows XP workstations was hit by the Sasser worm a while back and he has fixed that up.
Now I suspect that the consultants might not have configured his SMTP virtual server properly and it has allowed open relay? As a result they've been a victim of SPAM repaying.
Could it also be a virus??
I'm going to go over there and have a look at that this afternoon. Anyone has any ideas? I plan to bring over with me ethereal. Would that be enough to find out what's going on with the packets being sent out? I've never used it before would the default settings be alrigh for this task??
Thanks all for any help / hints.