Work email, need help BAD ***EDIT**SOLVED!

mboy

Diamond Member
Jul 29, 2001
3,309
0
0
Update***
Well, manually deleting ALL of the emails in the problem users accounts cleared the problem for now (still have corruption as it is shwoing a few accounts with emails in it and their are none thru Telnet. 1 account won't even let me telnet in, says password is bad, but I even reset it myself, so something fishy is going on. I do believe our mail server has been hijacked and is being used as a spam server. Tomorrow, changing over to our ISP hosting our email and will be looking into using Daemon within the next month or 2. Also getting a real firewall instead of this outdated crap.
Want to get your company to spend money when they say you have NO budget to work with? Have email/virus/intrusion problems and have them find it real quick.
Big thanx to EVERYONE that helped!



Here is the deal, I have an old Interjet email server that the person who hosts my domain POPS my email to, from there, outlook 97 and 2k log onto there to retrieve the stored emails. 1st the 97s started to not work, but upgrading them to 2k fixed it. Now the 2ks are starting to go too. Get the 0x800ccc0f error saying that the server termintated the connection. I am running an NT 4 network sp6a. Old PDC/fileserver was getting way too old to handle things so I upgraded to a Dell poweredge 1.13 640mb ram 36mb scsi raid 5. Promoted that to my pdc, havent transfered the files over yet. Now have the old PDC as a BDC along with another bdc that has RAS running for our sales people to dial into.
Email on my workstation is fine as are others, but what would keep 6 or 7people from losing their connection to the Interjet (which is also our gateway/firewall, but firewall was never set up right.
Is this some type of TCP/IP error with my network, or should it be more a problem with Outlook/Interjet.
Network is all on 10/100 unmanaged switches, about 60 PCs, all OLD as dirt (486s' P100s, p266s etc)
Email problem has been on win 98, and 2000 machines. Running Panda GVI anti virus as we got hit about a month ago unprotected of course. Email problems with 97 started waay before that tho.
I need help on this one BAAAD. I thought it could have been the new antivirus software, but uninstalled it and still can't get those computers to log into the email server. HELP!!!!!
 

Nothinman

Elite Member
Sep 14, 2001
30,672
0
0
Try a different email client, or hell even try telneting to the POP3 port and checking mail manually. That'll tell you if it's a client or server issue.

Also, it's bad practice to have your DCs do anything other than auth. I would have an older PC (a PII 266 would be more than enough, especially for only 60 clients) running as PDC and put the mail server on the Dell as a member server.
 

mboy

Diamond Member
Jul 29, 2001
3,309
0
0
Yeah, You are right on about the PDC, but thats the way they want it. My emasil serer is actusally a stand alone linux based thing. Acts as an email server, firewall and gateway. I think it has to be a network/ server issue since more then a couple of computers with diffferent OS and outlook versions are having a problem.
 

Nothinman

Elite Member
Sep 14, 2001
30,672
0
0
Don't tell them how you set it up, just do it right =)

Hell make up some official looking MS docs that say you should never use a PDC for anything but auth if you have to =)

Check the logs on the server, and use telnet to connect to the POP3 port and to make sure it's not a client issue.
 

mboy

Diamond Member
Jul 29, 2001
3,309
0
0
I found a log on the server that said their was a virtual circuit error on one of the networked computers (not necessarily one of the ones having a problem, butit may be since 6 people use email on that computer). Could this casue my problem? Should I be telnetting in from one of the computers that cant connect, or just any old problem? I can't see it being a server issue as my own workstation can get my email just fine as can others.
 

mboy

Diamond Member
Jul 29, 2001
3,309
0
0
Well, was able to telnet in from one of the computers that outlook cant connect. Could this be some kind of virus or tcp/ip problem? WTF HELP!
 

Nothinman

Elite Member
Sep 14, 2001
30,672
0
0
Not just telnet, telnet to the POP3 port and see if you can login and check their mail manually.
 

mboy

Diamond Member
Jul 29, 2001
3,309
0
0
Yes, I was able to telnet into port 110 on my mail server and view the messages manually.

EDIT**** I have 2 email boxes that it says are LOADED with messages, when I telnet it, I can not get a list. I think I am on to something here. However, one of the emails that outlook doesnt work, I am able to see the email list. Could the 2 that wont list be jamming up the server causing the others to have trouble?

The ones that wont list, did recieve new emails today and can do test emails sent from themselves, but the server is showing that they still have a ton of messages.
 

neopipil

Member
Feb 15, 2002
29
0
0
mboy,

I maybe totally off base here but here is something that might help.

It might be that for some reason the messages are getting mangled and when you try to list them or download them, the server does not know how to handle them so it terminates the connection. I've had this happen to me in the past. Deleting all email and starting fresh took care of the problem for me.

It sounds very simplistic but it's just another possibility. Let us know if you resolve the problem.

neopipil
 

mboy

Diamond Member
Jul 29, 2001
3,309
0
0
Wierd, when I go in and delete 5 messages in the admin account (the email server browser says their are over 1600 messages) telnet shows 5, they come right back after I delete them. WTF?
 

JustinLerner

Senior member
Mar 15, 2002
425
0
0
Could it have been an e-mail attack that is targeting specific accounts (like the admin account) by trying to overload the mailboxes with the same messages?
 

mboy

Diamond Member
Jul 29, 2001
3,309
0
0
Thats a good possibility, how do I tell? WHy would some clients work and others not?
 

Nothinman

Elite Member
Sep 14, 2001
30,672
0
0
What type of 'linux based thing' is it? Mail is normally stored in /var/mail/username or their home directory. You could move the mail file, send a new mail to them and see if it shows up, that would confirm a mess is screwed up then you could sort through the mail file you have afterwards.
 

mboy

Diamond Member
Jul 29, 2001
3,309
0
0
This is what it is: Interjet
That is the newewr one (which isn't even supported anymore). I have the Interjet 100.
Also, I am getting a lot of admin messages like this:


The original message was received at Wed, 15 May 2002 16:04:03 -0400 (EDT)
from localhost

----- Mail could not be delivered due to errors for the following email addresses -----
<mortgagelender@newslifeexpress.com>

----- Transcript of session follows -----
... while talking to mail.newslifeexpress.com.:
>>> RCPT To:<mortgagelender@newslifeexpress.com>
<<< 550 unknown user <mortgagelender@newslifeexpress.com>
550 <mortgagelender@newslifeexpress.com>... User unknown

I have been getting a bunch of various stuff like this. WTF is that?
 

Nothinman

Elite Member
Sep 14, 2001
30,672
0
0
Looks like someone either type-o'd the address (mortgagelender@newslifeexpress.com) or someone's spamming through you.
 

mboy

Diamond Member
Jul 29, 2001
3,309
0
0
I get Boatloads of stuff like that. Looks like someone probably is spamming thru me. How do I find out, how do I stop it and could something like this be the root of all my evails? I am really under the gun with this as the owner of my company and his 2 sons are among the 6 or 7 of the emails which I can't get thru outlook. Could a virus be causing this as well? Found Klez in one of the emails on a workstation today, altho my antivirus deleted it.