exo
19-08-2008, 16:30
Доброго дня. Одна надежда на мой любимый форум.
Windows Server 2003 + Exchange 2003 + OWA
шлюз в интернет через ISA 2004
вот логи с ISЫ:
http://www.exonix.ru/log-isa.jpg
вот netstat -b c почтового сервера
TCP exch:27493 DC1.domain.local:1025 ESTABLISHED 20904
[mad.exe]
TCP exch:29949 DC1.domain.local:3268 ESTABLISHED 23872
[store.exe]
TCP exch:30087 DC1.domain.local:ldap ESTABLISHED 20904
[mad.exe]
TCP exch:30094 DC1.domain.local:3268 ESTABLISHED 3832
[wmiprvse.exe]
TCP exch:30101 DC1.domain.local:3268 ESTABLISHED 24572
[emsmta.exe]
TCP exch:30240 DC1.domain.local:ldap ESTABLISHED 20904
[mad.exe]
TCP exch:31263 DC1.domain.local:3268 ESTABLISHED 41080
[inetinfo.exe]
TCP exch:31390 exch.domain.local:691 ESTABLISHED 23872
[store.exe]
TCP exch:31391 exch.domain.local:691 ESTABLISHED 3832
[wmiprvse.exe]
TCP exch:31396 exch.domain.local:691 ESTABLISHED 24572
[emsmta.exe]
TCP exch:32535 exch.domain.local:691 ESTABLISHED 41080
[inetinfo.exe]
TCP exch:32538 DC2.domain.local:ldap ESTABLISHED 41080
[inetinfo.exe]
TCP exch:32540 DC2.domain.local:ldap ESTABLISHED 41080
[inetinfo.exe]
TCP exch:32541 DC1.domain.local:3268 ESTABLISHED 41080
[inetinfo.exe]
TCP exch:32543 DC2.domain.local:ldap ESTABLISHED 41080
[inetinfo.exe]
TCP exch:32545 DC1.domain.local:3268 CLOSE_WAIT 41080
[inetinfo.exe]
TCP exch:32546 DC1.domain.local:3268 CLOSE_WAIT 41080
[inetinfo.exe]
TCP exch:32547 DC1.domain.local:3268 CLOSE_WAIT 41080
[inetinfo.exe]
TCP exch:32553 DC1.domain.local:3268 CLOSE_WAIT 41080
[inetinfo.exe]
TCP exch:32554 DC1.domain.local:3268 CLOSE_WAIT 41080
[inetinfo.exe]
TCP exch:32703 DC2.domain.local:ldap CLOSE_WAIT 20904
[mad.exe]
TCP exch:smtp dsl-243-111-25.telkomadsl.co.za:59645 TIME_WAIT
0
TCP exch:smtp 58.146.223.37:20966 TIME_WAIT 0
TCP exch:smtp 62.118.175.6:52866 TIME_WAIT 0
TCP exch:smtp static-68-162-86-174.phil.east.verizon.net:2445
TIME_WAIT 0
TCP exch:smtp mail.TERRACOMPANY.com:50334 TIME_WAIT 0
TCP exch:smtp pool-72-92-89-212.phlapa.fios.verizon.net:52760
TIME_WAIT 0
TCP exch:smtp ppp78-37-151-209.pppoe.avangarddsl.ru:54963 TIM
E_WAIT 0
TCP exch:smtp adsl-dyn60.78-99-126.t-com.sk:48049 TIME_WAIT
0
TCP exch:smtp adsl-dyn140.78-99-144.t-com.sk:52751 TIME_WAIT
0
TCP exch:smtp g64148.upc-g.chello.nl:3476 TIME_WAIT 0
TCP exch:smtp 82-138-50-82.amigos.ncp.ru:3043 TIME_WAIT
0
TCP exch:smtp Univer-neft.Moscow.access.comstar.ru:59394 TIME
_WAIT 0
TCP exch:smtp 87-205-69-171.adsl.inetia.pl:56249 TIME_WAIT
0
TCP exch:smtp 88.235.40.77:28745 TIME_WAIT 0
TCP exch:smtp 88.252.148.55:52326 TIME_WAIT 0
TCP exch:smtp 92.83.78.92:12029 TIME_WAIT 0
TCP exch:smtp shpd-92-101-147-162.vologda.ru:59163 TIME_WAIT
0
TCP exch:smtp 5-128-113-92.pool.ukrtel.net:2233 TIME_WAIT
0
и вот нашёл в почтовом сервере:
http://www.exonix.ru/4to.jpg
Релей разрешён только на один IP - факс - отправляющий письма.
Но я думаю, его врятли можно использовать для отправки спама.
Помогите побороть исходящий спам.
Windows Server 2003 + Exchange 2003 + OWA
шлюз в интернет через ISA 2004
вот логи с ISЫ:
http://www.exonix.ru/log-isa.jpg
вот netstat -b c почтового сервера
TCP exch:27493 DC1.domain.local:1025 ESTABLISHED 20904
[mad.exe]
TCP exch:29949 DC1.domain.local:3268 ESTABLISHED 23872
[store.exe]
TCP exch:30087 DC1.domain.local:ldap ESTABLISHED 20904
[mad.exe]
TCP exch:30094 DC1.domain.local:3268 ESTABLISHED 3832
[wmiprvse.exe]
TCP exch:30101 DC1.domain.local:3268 ESTABLISHED 24572
[emsmta.exe]
TCP exch:30240 DC1.domain.local:ldap ESTABLISHED 20904
[mad.exe]
TCP exch:31263 DC1.domain.local:3268 ESTABLISHED 41080
[inetinfo.exe]
TCP exch:31390 exch.domain.local:691 ESTABLISHED 23872
[store.exe]
TCP exch:31391 exch.domain.local:691 ESTABLISHED 3832
[wmiprvse.exe]
TCP exch:31396 exch.domain.local:691 ESTABLISHED 24572
[emsmta.exe]
TCP exch:32535 exch.domain.local:691 ESTABLISHED 41080
[inetinfo.exe]
TCP exch:32538 DC2.domain.local:ldap ESTABLISHED 41080
[inetinfo.exe]
TCP exch:32540 DC2.domain.local:ldap ESTABLISHED 41080
[inetinfo.exe]
TCP exch:32541 DC1.domain.local:3268 ESTABLISHED 41080
[inetinfo.exe]
TCP exch:32543 DC2.domain.local:ldap ESTABLISHED 41080
[inetinfo.exe]
TCP exch:32545 DC1.domain.local:3268 CLOSE_WAIT 41080
[inetinfo.exe]
TCP exch:32546 DC1.domain.local:3268 CLOSE_WAIT 41080
[inetinfo.exe]
TCP exch:32547 DC1.domain.local:3268 CLOSE_WAIT 41080
[inetinfo.exe]
TCP exch:32553 DC1.domain.local:3268 CLOSE_WAIT 41080
[inetinfo.exe]
TCP exch:32554 DC1.domain.local:3268 CLOSE_WAIT 41080
[inetinfo.exe]
TCP exch:32703 DC2.domain.local:ldap CLOSE_WAIT 20904
[mad.exe]
TCP exch:smtp dsl-243-111-25.telkomadsl.co.za:59645 TIME_WAIT
0
TCP exch:smtp 58.146.223.37:20966 TIME_WAIT 0
TCP exch:smtp 62.118.175.6:52866 TIME_WAIT 0
TCP exch:smtp static-68-162-86-174.phil.east.verizon.net:2445
TIME_WAIT 0
TCP exch:smtp mail.TERRACOMPANY.com:50334 TIME_WAIT 0
TCP exch:smtp pool-72-92-89-212.phlapa.fios.verizon.net:52760
TIME_WAIT 0
TCP exch:smtp ppp78-37-151-209.pppoe.avangarddsl.ru:54963 TIM
E_WAIT 0
TCP exch:smtp adsl-dyn60.78-99-126.t-com.sk:48049 TIME_WAIT
0
TCP exch:smtp adsl-dyn140.78-99-144.t-com.sk:52751 TIME_WAIT
0
TCP exch:smtp g64148.upc-g.chello.nl:3476 TIME_WAIT 0
TCP exch:smtp 82-138-50-82.amigos.ncp.ru:3043 TIME_WAIT
0
TCP exch:smtp Univer-neft.Moscow.access.comstar.ru:59394 TIME
_WAIT 0
TCP exch:smtp 87-205-69-171.adsl.inetia.pl:56249 TIME_WAIT
0
TCP exch:smtp 88.235.40.77:28745 TIME_WAIT 0
TCP exch:smtp 88.252.148.55:52326 TIME_WAIT 0
TCP exch:smtp 92.83.78.92:12029 TIME_WAIT 0
TCP exch:smtp shpd-92-101-147-162.vologda.ru:59163 TIME_WAIT
0
TCP exch:smtp 5-128-113-92.pool.ukrtel.net:2233 TIME_WAIT
0
и вот нашёл в почтовом сервере:
http://www.exonix.ru/4to.jpg
Релей разрешён только на один IP - факс - отправляющий письма.
Но я думаю, его врятли можно использовать для отправки спама.
Помогите побороть исходящий спам.