Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » ISP Blocked my access because of spam
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
The Pirate Bay targeted by spammers and scammers: watch out! »
« After Boclean , What to use ?  
AuthorAll Replies

bofkentucky

join:2009-03-30
Louisville, KY


1 edit
reply to Kentucky Joe
Re: ISP Blocked my access because of spam

Start with the basics

1) Do you have a router in between your cable modem and your computer(s)?
2) Does the router have a DMZ port turned on?
3) Does the router have a firewall turned on?
4) Is the router wireless?
5) Is the wireless secured (SSID isn't broadcast and requires a wpa key)?
6) I'm guessing you're running windows. On each computer in your house do the following to see if you have a mail server running
click on start
click on run
type cmd.exe in the open box
hit enter
You should have a dos prompt open now
in that you need to type netstat -an

If you see a line like the next two (x.y.z.a and b.c.d.e are ip addresses like 0.0.0.0 or 192.168.1.20 or 74.128.17.114 for example)

TCP x.y.z.a:25 b.c.d.e LISTENING

or

TCP x.y.z.a:587 b.c.d.e LISTENING

You do have a mail server running on that computer. It's time to antivirus/antispyware that computer until those ports aren't listening. Check for programs that we're installed recently.


leibold
Premium,MVM
join:2002-07-09
Sunnyvale, CA
clubs:

Everything you said is correct for detecting that a regular mailserver is running on the system that allows for incoming email.
However the ISP complained about email send (not received) by "Kentucky Joe". If his computer is infected with a trojan/virus the software will use a mail client to transmit the email or have an embedded mail server solely for sending email with bothering to receive email.
Looking for any ports in listening state is still useful, because the trojan/virus may have established a backdoor to allow remote control of the computer. However that backdoor may not be listening on standard email ports.

Assuming that the ISP correctly identified "Kentucky Joe's" internet connection as the source of the spam and further assuming he isn't deliberately sending spam the two most likely explanations are:
1.) one (or more) of the computers on his home network is(are) infected and need to be cleaned up.
2.) someone else in the neighborhood is making unauthorized use of his wireless network.
--
Got some spare cpu cycles ? Join Team Helix or Team Starfire!


nwrickert
sand groper
Premium,MVM
join:2004-09-04
Geneva, IL
·AT&T U-Verse
·AT&T Midwest

said by leibold See Profile :

1.) one (or more) of the computers on his home network is(are) infected and need to be cleaned up.
2.) someone else in the neighborhood is making unauthorized use of his wireless network.
Yes, good analysis. These possibilities are what the OP needs to check.

Attempting to block the outgoing mail would just be a bandaid solution, and probably not very effective. Securing the wireless network (if one is used), and cleaning out the malware on all computers on the home LAN is the way to deal with this problem.
--
AT&T dsl; Westell 327w modem/router; openSuSE 11.0; firefox 3.0.10
-
Forums » Up and Running » Security » SecurityThe Pirate Bay targeted by spammers and scammers: watch out! »
« After Boclean , What to use ?  


Tuesday, 01-Dec 10:53:57 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [62] Baltimore To Ban Lazy Cable Installs
· [53] Broadband Killed The Game Console
· [38] Rural Carriers Quickly Embracing Fiber
· [33] AT&T Top Lobbyist Cicconi Has His Feelings Hurt
· [30] Charter Exits Chapter 11
· [26] Rogers Unveils The ISP Dream Model
· [22] Midcontinent Socked With Easement Lawsuit
· [10] Vivendi Agrees, Comcast/NBC Deal Soon
· [9] ACTA: Global Three Strikes
· [4] Monday Evening Links
Most people now reading
· [Rant] called out sick! [Rants, Raves, and Praise]
· Heating - my dad gave me this advice... [Home Repair & Improvement]
· Is Microsoft Technet ok to use for my family PC's? [Microsoft Help]
· buying a one way ticket [General Questions]
· Windows 7 boot manager editing questions [Microsoft Help]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· Fun screwing with PuG raids. [World of Warcraft]
· Prevx says MS Nov 10 patches causing BSOD problems [Security]
· Callcentric and 3-way calling [VOIP Tech Chat]