Community Discussions and Support
Our Mercury/32 suddenly behaves as open relay HELP !!!!!

AUTH CRAM-MD5 rehashes the password, but the userid is the important bit anyway.

Change that users password - and keep watching your logs...

<p>AUTH CRAM-MD5 rehashes the password, but the userid is the important bit anyway.</p><p>Change that users password - and keep watching your logs... </p>

This morning i noticed thousand delivery errors and i seen a lot of outgoing SMAP messages apparently routed by our mailserver !

Messages was i.e. from aliquam@aliquam.edu to elzehem@yahoo.com etc ...

Our server is configured to be NOT open relay and the authentication is imposed (i manage file AUTH.MER to do this), but messages continue to arrive and forwarded !

I do not understand this problem, some ideas ?!?

ALex.

<P>This morning i noticed thousand delivery errors and i seen a lot of outgoing SMAP messages apparently routed by our mailserver !</P> <P>Messages was i.e. from <A href="mailto:aliquam@aliquam.edu" mce_href="mailto:aliquam@aliquam.edu">aliquam@aliquam.edu</A> to <A href="mailto:elzehem@yahoo.com" mce_href="mailto:elzehem@yahoo.com">elzehem@yahoo.com</A> etc ...</P> <P>Our server is configured to be NOT open relay and the authentication is imposed (i manage file AUTH.MER to do this), but messages <SPAN id=result_box lang=en class=short_text closure_uid_f4ehkr="127" a="undefined" c="4"><SPAN class=hps closure_uid_f4ehkr="394">continue to arrive</SPAN> <SPAN class=hps closure_uid_f4ehkr="395">and forwarded !</SPAN></SPAN></P> <P><SPAN id=result_box lang=en class=short_text closure_uid_f4ehkr="127" a="undefined" c="4"><SPAN class=hps closure_uid_f4ehkr="342">I do not understand</SPAN> <SPAN class=hps closure_uid_f4ehkr="343">this </SPAN><SPAN class=hps closure_uid_f4ehkr="344">problem, some ideas ?!?</SPAN></SPAN></P> <P><SPAN lang=en class=short_text closure_uid_f4ehkr="127" a="undefined" c="4"><SPAN class=hps closure_uid_f4ehkr="344">ALex.</SPAN></SPAN></P>

Messages transiting in our server has this form:

"Received: from spooler by mydomain.com (Mercury/32 v4.52); 21 Jan 2013 09:36:50 +0100
Received: from Unknown (88.40.127.38) by mercury.mydomain.com (Mercury/32 v4.52) with ESMTP ID MG000B5E;
   21 Jan 2013 09:36:45 +0100
Message-ID: <22D859FBCEF749C5887DA669D2DB1683@efnr>
From: "Sylvia" <ut@velitegetlaoreet.ca>
To: <ajcafonso@hotmail.com>
Subject: are you here? please read my letter. I need just one minute of your time.
Date: Mon, 21 Jan 2013 02:36:11 -0600
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="----=_NextPart_000_1387_01CDF780.13540380"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Windows Live Mail 16.4.3505.912
X-MimeOLE: Produced By Microsoft MimeOLE V16.4.3505.912

This is a multi-part message in MIME format.

------=_NextPart_000_1387_01CDF780.13540380
Content-Type: multipart/alternative;
boundary="----=_NextPart_001_1388_01CDF780.13540380"


------=_NextPart_001_1388_01CDF780.13540380
Content-Type: text/plain;
charset="windows-1251"
Content-Transfer-Encoding: quoted-printable

Hello my dear friend, I hope you remember me. Some time ago, we have acqu=
ante with you on a dating site.You leave me your e-mail on this site ..."

... etc

 No FROM nor TO involves my domain, but message is delivered exactly as an open relay ...

ALex.

&lt;P&gt;Messages transiting in our server has this form:&lt;/P&gt; &lt;P&gt;&lt;EM&gt;&quot;Received: from spooler by &lt;STRONG&gt;mydomain.com&lt;/STRONG&gt;&amp;nbsp;(Mercury/32 v4.52); 21 Jan 2013 09:36:50 +0100 Received: from Unknown (88.40.127.38) by mercury.&lt;STRONG&gt;mydomain.com&lt;/STRONG&gt;&amp;nbsp;(Mercury/32 v4.52) with ESMTP ID MG000B5E; &amp;nbsp;&amp;nbsp; 21 Jan 2013 09:36:45 +0100 Message-ID: &amp;lt;22D859FBCEF749C5887DA669D2DB1683@efnr&amp;gt; From: &quot;Sylvia&quot; &amp;lt;ut@velitegetlaoreet.ca&amp;gt; To: &amp;lt;ajcafonso@hotmail.com&amp;gt; Subject: are you here? please read my letter. I need just one minute of your time. Date: Mon, 21 Jan 2013 02:36:11 -0600 MIME-Version: 1.0 Content-Type: multipart/mixed; boundary=&quot;----=_NextPart_000_1387_01CDF780.13540380&quot; X-Priority: 3 X-MSMail-Priority: Normal X-Mailer: Microsoft Windows Live Mail 16.4.3505.912 X-MimeOLE: Produced By Microsoft MimeOLE V16.4.3505.912 This is a multi-part message in MIME format. ------=_NextPart_000_1387_01CDF780.13540380 Content-Type: multipart/alternative; boundary=&quot;----=_NextPart_001_1388_01CDF780.13540380&quot; ------=_NextPart_001_1388_01CDF780.13540380 Content-Type: text/plain; charset=&quot;windows-1251&quot; Content-Transfer-Encoding: quoted-printable Hello my dear friend, I hope you remember me. Some time ago, we have acqu= ante with you on a dating site.You leave me your e-mail on this site ...&quot;&lt;/EM&gt;&lt;/P&gt; &lt;P&gt;... etc&lt;/P&gt; &lt;P&gt;&amp;nbsp;No &lt;STRONG&gt;FROM&lt;/STRONG&gt; nor &lt;STRONG&gt;TO&lt;/STRONG&gt; involves &lt;STRONG&gt;my domain&lt;/STRONG&gt;, but message is delivered exactly as an open relay ...&lt;/P&gt; &lt;P&gt;ALex. &lt;/P&gt;

Below a typical connection history from SMTP log:

T 20130121 001043 50fb2221 Connection from 62.205.6.250
T 20130121 001043 50fb2221 EHLO Unknown
T 20130121 001044 50fb2221 AUTH CRAM-MD5
T 20130121 001044 50fb2221 MAIL FROM:<et@quisarcu.com>
T 20130121 001044 50fb2221 RCPT TO:<lauriki_10@hotmail.com>
T 20130121 001046 50fb2221 DATA - 952 lines, 70942 bytes.
T 20130121 001046 50fb2221 QUIT
T 20130121 001046 50fb2221 Connection closed with 62.205.6.250, 3 sec. elapsed.

ALex.

&lt;P&gt;Below a typical connection history&amp;nbsp;from SMTP log:&lt;/P&gt; &lt;P&gt;T 20130121 001043 50fb2221 Connection from 62.205.6.250 T 20130121 001043 50fb2221 EHLO Unknown T 20130121 001044 50fb2221 AUTH CRAM-MD5 T 20130121 001044 50fb2221 MAIL FROM:&amp;lt;&lt;A href=&quot;mailto:et@quisarcu.com&quot;&gt;et@quisarcu.com&lt;/A&gt;&amp;gt; T 20130121 001044 50fb2221 RCPT TO:&amp;lt;&lt;A href=&quot;mailto:lauriki_10@hotmail.com&quot;&gt;lauriki_10@hotmail.com&lt;/A&gt;&amp;gt; T 20130121 001046 50fb2221 DATA - 952 lines, 70942 bytes. T 20130121 001046 50fb2221 QUIT T 20130121 001046 50fb2221 Connection closed with 62.205.6.250, 3 sec. elapsed. &lt;/P&gt; &lt;P&gt;ALex.&lt;/P&gt;

I suspect on that "AUTH CRAM-MD5" ... [:(]

 

ALex.

&lt;P&gt;I suspect on that &quot;AUTH CRAM-MD5&quot; ... [:(]&lt;/P&gt; &lt;P mce_keep=&quot;true&quot;&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;ALex.&lt;/P&gt;

As I understand with authentification active and sucessful any mail will be accepted. You may disable relaying only on not authentificated connections.

So ... it seems at least one pair of username and password in your AUTH.MER is hacked.

 

&lt;p&gt;As I understand with authentification active and sucessful any mail will be accepted. You may disable relaying only on not authentificated connections.&lt;/p&gt;&lt;p&gt;So ... it seems at least one pair of username and password in your AUTH.MER is hacked.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;

[quote user="alexbromo"]

This morning i noticed thousand delivery errors and i seen a lot of outgoing SMAP messages apparently routed by our mailserver !

Messages was i.e. from aliquam@aliquam.edu to elzehem@yahoo.com etc ...

Our server is configured to be NOT open relay and the authentication is imposed (i manage file AUTH.MER to do this), but messages continue to arrive and forwarded ![/quote]

What boxes have you got ticked in MercuryS "Relaying control" ?

Is the spam all coming from the same IP address? Do you have any weak authentication passwords?

[quote user=&quot;alexbromo&quot;] &lt;P&gt;This morning i noticed thousand delivery errors and i seen a lot of outgoing SMAP messages apparently routed by our mailserver !&lt;/P&gt; &lt;P&gt;Messages was i.e. from &lt;A href=&quot;mailto:aliquam@aliquam.edu&quot; mce_href=&quot;mailto:aliquam@aliquam.edu&quot;&gt;aliquam@aliquam.edu&lt;/A&gt; to &lt;A href=&quot;mailto:elzehem@yahoo.com&quot; mce_href=&quot;mailto:elzehem@yahoo.com&quot;&gt;elzehem@yahoo.com&lt;/A&gt; etc ...&lt;/P&gt; &lt;P&gt;Our server is configured to be NOT open relay and the authentication is imposed (i manage file AUTH.MER to do this), but messages &lt;SPAN id=result_box lang=en class=short_text c=&quot;4&quot; a=&quot;undefined&quot; closure_uid_f4ehkr=&quot;127&quot;&gt;&lt;SPAN class=hps closure_uid_f4ehkr=&quot;394&quot;&gt;continue to arrive&lt;/SPAN&gt; &lt;SPAN class=hps closure_uid_f4ehkr=&quot;395&quot;&gt;and forwarded ![/quote]&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt; &lt;P&gt;&lt;SPAN lang=en class=short_text c=&quot;4&quot; a=&quot;undefined&quot; closure_uid_f4ehkr=&quot;127&quot;&gt;&lt;SPAN class=hps closure_uid_f4ehkr=&quot;395&quot;&gt;What boxes have you got ticked in MercuryS &quot;Relaying control&quot; ?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt; &lt;P&gt;&lt;SPAN lang=en class=short_text c=&quot;4&quot; a=&quot;undefined&quot; closure_uid_f4ehkr=&quot;127&quot;&gt;&lt;SPAN class=hps closure_uid_f4ehkr=&quot;395&quot;&gt;Is the spam all coming from the same IP address? Do you have any weak authentication&amp;nbsp;passwords? &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;

[quote user="FJR"]

As I understand with authentification active and sucessful any mail will be accepted. You may disable relaying only on not authentificated connections.

So ... it seems at least one pair of username and password in your AUTH.MER is hacked.

 

[/quote]

Thank you for reply.

It is possible that some user's password has been hacked ... how to verify what username/password is used to gain authorization to our SMTP ?

Thanks.

ALex.

[quote user=&quot;FJR&quot;] &lt;P&gt;As I understand with authentification active and sucessful any mail will be accepted. You may disable relaying only on not authentificated connections.&lt;/P&gt; &lt;P&gt;So ... it seems at least one pair of username and password in your AUTH.MER is hacked.&lt;/P&gt; &lt;P mce_keep=&quot;true&quot;&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;[/quote]&lt;/P&gt; &lt;P&gt;Thank you for reply.&lt;/P&gt; &lt;P&gt;It is possible that some user&#039;s password has been hacked ... how to verify what username/password is used to gain authorization to our SMTP ? &lt;/P&gt; &lt;P&gt;Thanks.&lt;/P&gt; &lt;P&gt;ALex.&lt;/P&gt;

This is my SMTP Connection control configuration that works well for many years: all four checks:

The SPAM is coming from hundred different addresses !

 ALex.

&lt;P&gt;This is my SMTP Connection control configuration that &lt;SPAN id=result_box lang=en class=short_text a=&quot;undefined&quot; c=&quot;4&quot; closure_uid_29vtdx=&quot;112&quot;&gt;&lt;SPAN class=hps closure_uid_29vtdx=&quot;192&quot;&gt;works well&lt;/SPAN&gt; &lt;SPAN class=hps closure_uid_29vtdx=&quot;193&quot;&gt;for many years: all four checks:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt; &lt;P&gt;&lt;SPAN lang=en class=short_text a=&quot;undefined&quot; c=&quot;4&quot; closure_uid_29vtdx=&quot;112&quot;&gt;&lt;SPAN class=hps closure_uid_29vtdx=&quot;193&quot;&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;IMG src=&quot;http://img521.imageshack.us/img521/1590/smtp1.jpg&quot; mce_src=&quot;http://img521.imageshack.us/img521/1590/smtp1.jpg&quot;&gt;&lt;/P&gt; &lt;P&gt;The SPAM is coming from hundred different addresses !&lt;/P&gt; &lt;P&gt;&amp;nbsp;ALex.&lt;/P&gt;

[quote user="alexbromo"]

This is my SMTP Connection control configuration that works well for many years: all four checks:

The SPAM is coming from hundred different addresses ![/quote]

How many users are in the auth.mer file?  If it isn't obvious which is the "guessable" password, you may find out something from a session log from a spam run.

 

[quote user=&quot;alexbromo&quot;] &lt;P&gt;This is my SMTP Connection control configuration that &lt;SPAN id=result_box lang=en class=short_text c=&quot;4&quot; a=&quot;undefined&quot; closure_uid_29vtdx=&quot;112&quot;&gt;&lt;SPAN class=hps closure_uid_29vtdx=&quot;192&quot;&gt;works well&lt;/SPAN&gt; &lt;SPAN class=hps closure_uid_29vtdx=&quot;193&quot;&gt;for many years: all four checks:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt; &lt;P&gt;The SPAM is coming from hundred different addresses ![/quote]&lt;/P&gt; &lt;P&gt;How many users are in the auth.mer file?&amp;nbsp; If it isn&#039;t obvious which is the &quot;guessable&quot; password, you &lt;U&gt;may&lt;/U&gt;&amp;nbsp;find out something from a session log from a spam run.&lt;/P&gt; &lt;P mce_keep=&quot;true&quot;&gt;&amp;nbsp;&lt;/P&gt;

We have approximately an hundred users in the AUTH.MER

I have the session logging, but only string about login is "250-AUTH CRAM-MD5 LOGIN <cr><lf>" and no username is reported, so how to see what password was hacked ?

ALex.

&lt;P&gt;We have approximately an hundred users in the AUTH.MER&lt;/P&gt; &lt;P&gt;I have the session logging, but only string about login is &quot;250-AUTH CRAM-MD5&amp;nbsp;LOGIN &amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt;&quot; and no username is reported, so how to see what password was hacked ?&lt;/P&gt; &lt;P&gt;ALex.&lt;/P&gt;

[quote user="alexbromo"]We have approximately an hundred users in the AUTH.MER[/quote]

And none of them use "password" or "123456" etc?

[quote]I have the session logging, but only string about login is "250-AUTH CRAM-MD5 LOGIN <cr><lf>" and no username is reported, so how to see what password was hacked ?[/quote]

That is the advertisment being sent from your server.  Further on is the encoded authentication. The user name is base64 encoded - use a website like http://www.base64decode.org/ to find out the name.

&lt;P&gt;[quote user=&quot;alexbromo&quot;]We have approximately an hundred users in the AUTH.MER[/quote]&lt;/P&gt; &lt;P&gt;And none of them use &quot;password&quot; or &quot;123456&quot; etc?&lt;/P&gt; &lt;P&gt;[quote]I have the session logging, but only string about login is &quot;250-AUTH CRAM-MD5&amp;nbsp;LOGIN &amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt;&quot; and no username is reported, so how to see what password was hacked ?[/quote]&lt;/P&gt; &lt;P&gt;That is the advertisment being sent from your server.&amp;nbsp; Further on is the encoded authentication. The user name is base64 encoded - use a website like &lt;A href=&quot;http://www.base64decode.org/&quot;&gt;http://www.base64decode.org/&lt;/A&gt;&amp;nbsp;to find out the name.&lt;/P&gt;

[quote user="alexbromo"]It is possible that some user's password has been hacked ... how to verify what username/password is used to gain authorization to our SMTP ?[/quote]

I'm not shure, because I don't use AUTH.MER (have Novell Netware with eDiretory). May be you have temporarily to enable session logging on module SMTPS and have a look there.

&lt;p&gt;[quote user=&quot;alexbromo&quot;]It is possible that some user&#039;s password has been hacked ... how to verify what username/password is used to gain authorization to our SMTP ?[/quote]&lt;/p&gt;&lt;p&gt;I&#039;m not shure, because I don&#039;t use AUTH.MER (have Novell Netware with eDiretory). May be you have temporarily to enable session logging on module SMTPS and have a look there. &lt;/p&gt;

To place a momentary patch, should be an idea to place a filtering rule that permit outgoing only messages that match the criteria:

1) source mailbox contains "mydomain.com" + destination mailbox contains any domain

2) source mailbox name contains any domain and destination mailbox contains "mydomain.com"

other discarded !

ALex.

&lt;P&gt;To place a &lt;SPAN id=result_box lang=en class=short_text a=&quot;undefined&quot; c=&quot;4&quot; closure_uid_29vtdx=&quot;112&quot;&gt;&lt;SPAN class=hps closure_uid_29vtdx=&quot;251&quot;&gt;momentary patch, should be an idea to place a filtering rule that &lt;STRONG&gt;permit outgoing only messages that&amp;nbsp;match the criteria&lt;/STRONG&gt;:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt; &lt;P&gt;&lt;SPAN lang=en class=short_text a=&quot;undefined&quot; c=&quot;4&quot; closure_uid_29vtdx=&quot;112&quot;&gt;&lt;SPAN class=hps closure_uid_29vtdx=&quot;251&quot;&gt;1) source mailbox&amp;nbsp;contains&amp;nbsp;&quot;m&lt;SPAN id=result_box lang=en class=short_text a=&quot;undefined&quot; c=&quot;4&quot; closure_uid_29vtdx=&quot;112&quot;&gt;&lt;SPAN class=hps closure_uid_29vtdx=&quot;300&quot;&gt;ydomain.com&quot; +&amp;nbsp;destination mailbox contains&amp;nbsp;any domain&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt; &lt;P&gt;&lt;SPAN lang=en class=short_text a=&quot;undefined&quot; c=&quot;4&quot; closure_uid_29vtdx=&quot;112&quot;&gt;&lt;SPAN class=hps closure_uid_29vtdx=&quot;251&quot;&gt;&lt;SPAN lang=en class=short_text a=&quot;undefined&quot; c=&quot;4&quot; closure_uid_29vtdx=&quot;112&quot;&gt;&lt;SPAN class=hps closure_uid_29vtdx=&quot;300&quot;&gt;2) source mailbox name contains&amp;nbsp;any domain &lt;SPAN id=result_box lang=en class=short_text a=&quot;undefined&quot; c=&quot;4&quot; closure_uid_29vtdx=&quot;112&quot;&gt;&lt;SPAN class=hps closure_uid_29vtdx=&quot;300&quot;&gt;and destination mailbox contains &quot;m&lt;SPAN id=result_box lang=en class=short_text a=&quot;undefined&quot; c=&quot;4&quot; closure_uid_29vtdx=&quot;112&quot;&gt;&lt;SPAN class=hps closure_uid_29vtdx=&quot;300&quot;&gt;ydomain.com&quot;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt; &lt;P&gt;&lt;SPAN lang=en class=short_text a=&quot;undefined&quot; c=&quot;4&quot; closure_uid_29vtdx=&quot;112&quot;&gt;&lt;SPAN class=hps closure_uid_29vtdx=&quot;251&quot;&gt;&lt;SPAN lang=en class=short_text a=&quot;undefined&quot; c=&quot;4&quot; closure_uid_29vtdx=&quot;112&quot;&gt;&lt;SPAN class=hps closure_uid_29vtdx=&quot;300&quot;&gt;&lt;SPAN lang=en class=short_text a=&quot;undefined&quot; c=&quot;4&quot; closure_uid_29vtdx=&quot;112&quot;&gt;&lt;SPAN class=hps closure_uid_29vtdx=&quot;300&quot;&gt;&lt;SPAN lang=en class=short_text a=&quot;undefined&quot; c=&quot;4&quot; closure_uid_29vtdx=&quot;112&quot;&gt;&lt;SPAN class=hps closure_uid_29vtdx=&quot;300&quot;&gt;other discarded !&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt; &lt;P&gt;&lt;SPAN lang=en class=short_text a=&quot;undefined&quot; c=&quot;4&quot; closure_uid_29vtdx=&quot;112&quot;&gt;&lt;SPAN class=hps closure_uid_29vtdx=&quot;251&quot;&gt;&lt;SPAN lang=en class=short_text a=&quot;undefined&quot; c=&quot;4&quot; closure_uid_29vtdx=&quot;112&quot;&gt;&lt;SPAN class=hps closure_uid_29vtdx=&quot;300&quot;&gt;&lt;SPAN lang=en class=short_text a=&quot;undefined&quot; c=&quot;4&quot; closure_uid_29vtdx=&quot;112&quot;&gt;&lt;SPAN class=hps closure_uid_29vtdx=&quot;300&quot;&gt;&lt;SPAN lang=en class=short_text a=&quot;undefined&quot; c=&quot;4&quot; closure_uid_29vtdx=&quot;112&quot;&gt;&lt;SPAN class=hps closure_uid_29vtdx=&quot;300&quot;&gt;ALex.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;

[quote user="alexbromo"]

To place a momentary patch, should be an idea to place a filtering rule that permit outgoing only messages that match the criteria:

1) source mailbox contains "mydomain.com" + destination mailbox contains any domain

2) source mailbox name contains any domain and destination mailbox contains "mydomain.com"

other discarded ![/quote]

You would do the same by removing authentication and just keeping the first two relaying controls.  But if auth is used frequently then that may not be an option.

How are you getting on decoding the username?

[quote user=&quot;alexbromo&quot;] &lt;P&gt;To place a &lt;SPAN id=result_box lang=en class=short_text closure_uid_29vtdx=&quot;112&quot; c=&quot;4&quot; a=&quot;undefined&quot;&gt;&lt;SPAN class=hps closure_uid_29vtdx=&quot;251&quot;&gt;momentary patch, should be an idea to place a filtering rule that &lt;STRONG&gt;permit outgoing only messages that&amp;nbsp;match the criteria&lt;/STRONG&gt;:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt; &lt;P&gt;&lt;SPAN lang=en class=short_text closure_uid_29vtdx=&quot;112&quot; c=&quot;4&quot; a=&quot;undefined&quot;&gt;&lt;SPAN class=hps closure_uid_29vtdx=&quot;251&quot;&gt;1) source mailbox&amp;nbsp;contains&amp;nbsp;&quot;m&lt;SPAN id=result_box lang=en class=short_text closure_uid_29vtdx=&quot;112&quot; c=&quot;4&quot; a=&quot;undefined&quot;&gt;&lt;SPAN class=hps closure_uid_29vtdx=&quot;300&quot;&gt;ydomain.com&quot; +&amp;nbsp;destination mailbox contains&amp;nbsp;any domain&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt; &lt;P&gt;&lt;SPAN lang=en class=short_text closure_uid_29vtdx=&quot;112&quot; c=&quot;4&quot; a=&quot;undefined&quot;&gt;&lt;SPAN class=hps closure_uid_29vtdx=&quot;251&quot;&gt;&lt;SPAN lang=en class=short_text closure_uid_29vtdx=&quot;112&quot; c=&quot;4&quot; a=&quot;undefined&quot;&gt;&lt;SPAN class=hps closure_uid_29vtdx=&quot;300&quot;&gt;2) source mailbox name contains&amp;nbsp;any domain &lt;SPAN id=result_box lang=en class=short_text closure_uid_29vtdx=&quot;112&quot; c=&quot;4&quot; a=&quot;undefined&quot;&gt;&lt;SPAN class=hps closure_uid_29vtdx=&quot;300&quot;&gt;and destination mailbox contains &quot;m&lt;SPAN id=result_box lang=en class=short_text closure_uid_29vtdx=&quot;112&quot; c=&quot;4&quot; a=&quot;undefined&quot;&gt;&lt;SPAN class=hps closure_uid_29vtdx=&quot;300&quot;&gt;ydomain.com&quot;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt; &lt;P&gt;&lt;SPAN lang=en class=short_text closure_uid_29vtdx=&quot;112&quot; c=&quot;4&quot; a=&quot;undefined&quot;&gt;&lt;SPAN class=hps closure_uid_29vtdx=&quot;251&quot;&gt;&lt;SPAN lang=en class=short_text closure_uid_29vtdx=&quot;112&quot; c=&quot;4&quot; a=&quot;undefined&quot;&gt;&lt;SPAN class=hps closure_uid_29vtdx=&quot;300&quot;&gt;&lt;SPAN lang=en class=short_text closure_uid_29vtdx=&quot;112&quot; c=&quot;4&quot; a=&quot;undefined&quot;&gt;&lt;SPAN class=hps closure_uid_29vtdx=&quot;300&quot;&gt;&lt;SPAN lang=en class=short_text closure_uid_29vtdx=&quot;112&quot; c=&quot;4&quot; a=&quot;undefined&quot;&gt;&lt;SPAN class=hps closure_uid_29vtdx=&quot;300&quot;&gt;other discarded !&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;[/quote]&lt;/P&gt; &lt;P&gt;You would do the same by removing authentication and just keeping the first two relaying controls.&amp;nbsp; But if auth is used frequently then that may not be an option.&lt;/P&gt; &lt;P&gt;How are you getting on decoding the username?&lt;/P&gt;

This issue is a real mistery ...

Below a part of SMTP session logfile named TCP012F.MS and created some minutes ago :

09:03:29.937: Connection from 217.165.87.28, Mon Jan 21 09:03:29 2013<lf>
09:03:29.953: << 220 mercury.mydomain.com ESMTP server ready.<cr><lf>
09:03:29.578: >> EHLO Unknown<cr><lf>
09:03:29.578: << 250-mercury.mydomain.com Hello Unknown; ESMTPs are:<cr><lf>250-TIME<cr><lf>
09:03:29.578: << 250-SIZE 0<cr><lf>
09:03:29.578: << 250-AUTH CRAM-MD5 LOGIN<cr><lf>
09:03:29.578: << 250-AUTH=LOGIN<cr><lf>
09:03:29.578: << 250 HELP<cr><lf>
09:03:30.687: >> AUTH CRAM-MD5<cr><lf>
09:03:30.687: << 334 PDEwMjU2ODcuMzQ2QHBvbGl0ZWNuaWNhLml0Pg==<cr><lf>
09:03:31.203: >> bW51bnppIDc4ZWJjNTUxNWE2MTg2MmVlZWFkNGQ0ZWYyNDc2ZDZi<cr><lf>

Note that, translating from Base64:

PDEwMjU2ODcuMzQ2QHBvbGl0ZWNuaWNhLml0Pg -> <1025687.346@mydomain.com
bW51bnppIDc4ZWJjNTUxNWE2MTg2MmVlZWFkNGQ0ZWYyNDc2ZDZi -> mnunzi 78ebc5515a61862eeead4d4ef2476d6b

where the only string wit a sense is mnunzi that is a user of my Mercury/32 (but 78ebc5515a61862eeead4d4ef2476d6b is NOT the password ... where is the password ?) :(

Then LOG proceed with authentication successful (?!?) and the rest of message is sent ... (it is SPAM mail with a .ZIP attachment)

09:03:31.203: << 235 Authentication successful.<cr><lf>
09:03:31.796: >> MAIL FROM:<pede@ut.ca><cr><lf>
09:03:31.796: << 250 Sender OK - send RCPTs.<cr><lf>
09:03:32.359: >> RCPT TO:<adiyuda@telkom.net><cr><lf>
09:03:32.359: << 250 Recipient OK - send RCPT or DATA.<cr><lf>
09:03:33.015: >> DATA<cr><lf>
09:03:33.015: << 354 OK, send data, end with CRLF.CRLF<cr><lf>
09:03:33.625: >> Message-ID: <D78C518B305D43AA94DFE1EE3493F36E@upvua><cr><lf>
09:03:33.625: >> From: "Hyacinth" <pede@ut.ca><cr><lf>
09:03:33.625: >> To: <adiyuda@telkom.net><cr><lf>
09:03:33.625: >> Subject: This business life is taking all of me. I need vacation.<cr><lf>
09:03:33.625: >> Date: Mon, 21 Jan 2013 02:05:32 -0600<cr><lf>
09:03:33.625: >> MIME-Version: 1.0<cr><lf>
09:03:33.625: >> Content-Type: multipart/mixed;<cr><lf>
09:03:33.625: >> boundary="----=_NextPart_000_1998_01CDF77B.CB1288C0"<cr><lf>
09:03:33.625: >> X-Priority: 3<cr><lf>
09:03:33.625: >> X-MSMail-Priority: Normal<cr><lf>
09:03:33.625: >> X-Mailer: Microsoft Windows Mail 6.0.6001.18416<cr><lf>
09:03:33.625: >> X-MimeOLE: Produced By Microsoft MimeOLE V6.0.6001.18645<cr><lf>
09:03:33.625: >> <cr><lf>
09:03:33.625: >> This is a multi-part message in MIME format.<cr><lf>
09:03:33.625: >> <cr><lf>
09:03:33.625: >> ------=_NextPart_000_1998_01CDF77B.CB1288C0<cr><lf>
09:03:33.625: >> Content-Type: multipart/alternative;<cr><lf>
09:03:33.625: >> boundary="----=_NextPart_001_1999_01CDF77B.CB1288C0"<cr><lf>
09:03:33.625: >> <cr><lf>
09:03:33.625: >> <cr><lf>
....
....
"

[:'(]

ALex.

&lt;P&gt;This issue is a real mistery ...&lt;/P&gt; &lt;P&gt;Below a part of SMTP session logfile named TCP012F.MS and&amp;nbsp;created some minutes ago :&lt;/P&gt; &lt;P&gt;&lt;EM&gt;09:03:29.937: Connection from 217.165.87.28, Mon Jan 21 09:03:29 2013&amp;lt;lf&amp;gt; 09:03:29.953: &amp;lt;&amp;lt; 220 mercury.mydomain.com ESMTP server ready.&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 09:03:29.578: &amp;gt;&amp;gt; EHLO Unknown&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 09:03:29.578: &amp;lt;&amp;lt; 250-mercury.mydomain.com Hello Unknown; ESMTPs are:&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt;250-TIME&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 09:03:29.578: &amp;lt;&amp;lt; 250-SIZE 0&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 09:03:29.578: &amp;lt;&amp;lt; 250-AUTH CRAM-MD5 LOGIN&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 09:03:29.578: &amp;lt;&amp;lt; 250-AUTH=LOGIN&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 09:03:29.578: &amp;lt;&amp;lt; 250 HELP&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 09:03:30.687: &amp;gt;&amp;gt; AUTH CRAM-MD5&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 09:03:30.687: &amp;lt;&amp;lt; &lt;STRONG&gt;334 PDEwMjU2ODcuMzQ2QHBvbGl0ZWNuaWNhLml0Pg&lt;/STRONG&gt;==&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 09:03:31.203: &amp;gt;&amp;gt; &lt;STRONG&gt;bW51bnppIDc4ZWJjNTUxNWE2MTg2MmVlZWFkNGQ0ZWYyNDc2ZDZi&lt;/STRONG&gt;&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; &lt;/EM&gt;&lt;/P&gt; &lt;P&gt;Note that, translating from Base64:&lt;/P&gt; &lt;P&gt;PDEwMjU2ODcuMzQ2QHBvbGl0ZWNuaWNhLml0Pg -&amp;gt; &lt;STRONG&gt;&amp;lt;&lt;/STRONG&gt;&lt;A href=&quot;mailto:1025687.346@mydomain.com&quot; mce_href=&quot;mailto:1025687.346@mydomain.com&quot;&gt;&lt;STRONG&gt;1025687.346@mydomain.com&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt;&amp;gt;&amp;nbsp; &lt;/STRONG&gt;bW51bnppIDc4ZWJjNTUxNWE2MTg2MmVlZWFkNGQ0ZWYyNDc2ZDZi -&amp;gt; &lt;STRONG&gt;mnunzi 78ebc5515a61862eeead4d4ef2476d6b&lt;/STRONG&gt;&lt;/P&gt; &lt;P&gt;where the only string wit a sense is &lt;STRONG&gt;mnunzi&lt;/STRONG&gt; that&amp;nbsp;is a user of my&amp;nbsp;Mercury/32 (but 78ebc5515a61862eeead4d4ef2476d6b is NOT the password ... where is the password ?) :(&lt;/P&gt; &lt;P&gt;Then&amp;nbsp;LOG proceed&amp;nbsp;with authentication&amp;nbsp;successful (?!?) and the rest of message is sent ... (it is SPAM mail with&amp;nbsp;a .ZIP attachment)&lt;/P&gt; &lt;P&gt;&lt;EM&gt;09:03:31.203: &amp;lt;&amp;lt; 235 Authentication successful.&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 09:03:31.796: &amp;gt;&amp;gt; MAIL FROM:&amp;lt;pede@ut.ca&amp;gt;&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 09:03:31.796: &amp;lt;&amp;lt; 250 Sender OK - send RCPTs.&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 09:03:32.359: &amp;gt;&amp;gt; RCPT TO:&amp;lt;adiyuda@telkom.net&amp;gt;&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 09:03:32.359: &amp;lt;&amp;lt; 250 Recipient OK - send RCPT or DATA.&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 09:03:33.015: &amp;gt;&amp;gt; DATA&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 09:03:33.015: &amp;lt;&amp;lt; 354 OK, send data, end with CRLF.CRLF&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 09:03:33.625: &amp;gt;&amp;gt; Message-ID: &amp;lt;D78C518B305D43AA94DFE1EE3493F36E@upvua&amp;gt;&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 09:03:33.625: &amp;gt;&amp;gt; From: &quot;Hyacinth&quot; &amp;lt;pede@ut.ca&amp;gt;&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 09:03:33.625: &amp;gt;&amp;gt; To: &amp;lt;adiyuda@telkom.net&amp;gt;&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 09:03:33.625: &amp;gt;&amp;gt; Subject: This business life is taking all of me. I need vacation.&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 09:03:33.625: &amp;gt;&amp;gt; Date: Mon, 21 Jan 2013 02:05:32 -0600&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 09:03:33.625: &amp;gt;&amp;gt; MIME-Version: 1.0&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 09:03:33.625: &amp;gt;&amp;gt; Content-Type: multipart/mixed;&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 09:03:33.625: &amp;gt;&amp;gt; boundary=&quot;----=_NextPart_000_1998_01CDF77B.CB1288C0&quot;&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 09:03:33.625: &amp;gt;&amp;gt; X-Priority: 3&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 09:03:33.625: &amp;gt;&amp;gt; X-MSMail-Priority: Normal&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 09:03:33.625: &amp;gt;&amp;gt; X-Mailer: Microsoft Windows Mail 6.0.6001.18416&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 09:03:33.625: &amp;gt;&amp;gt; X-MimeOLE: Produced By Microsoft MimeOLE V6.0.6001.18645&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 09:03:33.625: &amp;gt;&amp;gt; &amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 09:03:33.625: &amp;gt;&amp;gt; This is a multi-part message in MIME format.&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 09:03:33.625: &amp;gt;&amp;gt; &amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 09:03:33.625: &amp;gt;&amp;gt; ------=_NextPart_000_1998_01CDF77B.CB1288C0&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 09:03:33.625: &amp;gt;&amp;gt; Content-Type: multipart/alternative;&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 09:03:33.625: &amp;gt;&amp;gt; boundary=&quot;----=_NextPart_001_1999_01CDF77B.CB1288C0&quot;&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 09:03:33.625: &amp;gt;&amp;gt; &amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 09:03:33.625: &amp;gt;&amp;gt; &amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; .... ....&lt;/EM&gt;&lt;EM&gt;&quot; &lt;/EM&gt;&lt;/P&gt; &lt;P&gt;&lt;EM&gt;[:&#039;(]&lt;/EM&gt;&lt;/P&gt; &lt;P&gt;&lt;EM&gt;ALex.&lt;/P&gt;&lt;/EM&gt;

[quote user="alexbromo"]This issue is a real mistery ...

Below a part of SMTP session logfile named TCP012F.MS and created some minutes ago :

09:03:30.687: >> AUTH CRAM-MD5<cr><lf>
09:03:30.687: << 334 PDEwMjU2ODcuMzQ2QHBvbGl0ZWNuaWNhLml0Pg==<cr><lf>
09:03:31.203: >> bW51bnppIDc4ZWJjNTUxNWE2MTg2MmVlZWFkNGQ0ZWYyNDc2ZDZi<cr><lf>

Note that, translating from Base64:

PDEwMjU2ODcuMzQ2QHBvbGl0ZWNuaWNhLml0Pg -> <1025687.346@mydomain.com
bW51bnppIDc4ZWJjNTUxNWE2MTg2MmVlZWFkNGQ0ZWYyNDc2ZDZi -> mnunzi 78ebc5515a61862eeead4d4ef2476d6b

where the only string wit a sense is mnunzi that is a user of my Mercury/32 (but 78ebc5515a61862eeead4d4ef2476d6b is NOT the password ... where is the password ?) :([/quote]

Because the sender has asked to use "AUTH CRAM-MD5", it's a salted hash of the password (read more at http://en.wikipedia.org/wiki/CRAM-MD5).

[quote]Then LOG proceed with authentication successful (?!?) and the rest of message is sent ... (it is SPAM mail with a .ZIP attachment)

09:03:31.203: << 235 Authentication successful.<cr><lf>
....
[/quote]

You have the username, now you can force the password change.

 

[quote user=&quot;alexbromo&quot;]This issue is a real mistery ... &lt;P&gt;Below a part of SMTP session logfile named TCP012F.MS and&amp;nbsp;created some minutes ago :&lt;/P&gt; &lt;P&gt;&lt;EM&gt;09:03:30.687: &amp;gt;&amp;gt; AUTH CRAM-MD5&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 09:03:30.687: &amp;lt;&amp;lt; &lt;STRONG&gt;334 PDEwMjU2ODcuMzQ2QHBvbGl0ZWNuaWNhLml0Pg&lt;/STRONG&gt;==&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 09:03:31.203: &amp;gt;&amp;gt; &lt;STRONG&gt;bW51bnppIDc4ZWJjNTUxNWE2MTg2MmVlZWFkNGQ0ZWYyNDc2ZDZi&lt;/STRONG&gt;&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; &lt;/EM&gt;&lt;/P&gt; &lt;P&gt;Note that, translating from Base64:&lt;/P&gt; &lt;P&gt;PDEwMjU2ODcuMzQ2QHBvbGl0ZWNuaWNhLml0Pg -&amp;gt; &lt;STRONG&gt;&amp;lt;&lt;/STRONG&gt;&lt;A href=&quot;mailto:1025687.346@mydomain.com&quot; mce_href=&quot;mailto:1025687.346@mydomain.com&quot;&gt;&lt;STRONG&gt;1025687.346@mydomain.com&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt;&amp;gt;&amp;nbsp; &lt;/STRONG&gt;bW51bnppIDc4ZWJjNTUxNWE2MTg2MmVlZWFkNGQ0ZWYyNDc2ZDZi -&amp;gt; &lt;STRONG&gt;mnunzi 78ebc5515a61862eeead4d4ef2476d6b&lt;/STRONG&gt;&lt;/P&gt; &lt;P&gt;where the only string wit a sense is &lt;STRONG&gt;mnunzi&lt;/STRONG&gt; that&amp;nbsp;is a user of my&amp;nbsp;Mercury/32 (but 78ebc5515a61862eeead4d4ef2476d6b is NOT the password ... where is the password ?) :([/quote]&lt;/P&gt; &lt;P&gt;Because the sender has asked to use &quot;AUTH CRAM-MD5&quot;, it&#039;s a salted hash of the password (read more at &lt;A href=&quot;http://en.wikipedia.org/wiki/CRAM-MD5&quot;&gt;http://en.wikipedia.org/wiki/CRAM-MD5&lt;/A&gt;).&lt;/P&gt; &lt;P&gt;[quote]Then&amp;nbsp;LOG proceed&amp;nbsp;with authentication&amp;nbsp;successful (?!?) and the rest of message is sent ... (it is SPAM mail with&amp;nbsp;a .ZIP attachment)&lt;/P&gt; &lt;P&gt;&lt;EM&gt;09:03:31.203: &amp;lt;&amp;lt; 235 Authentication successful.&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; ....&lt;/EM&gt;[/quote]&lt;/P&gt; &lt;P&gt;You have the username, now you can force the password change.&lt;/P&gt; &lt;P mce_keep=&quot;true&quot;&gt;&amp;nbsp;&lt;/P&gt;

I changed user's password, then i found a secondo user with account hacked and i changed his password too ...

I woluld know how this is possible ... perhaps exist a family of trojans that can steal users' password stored in the mail client (Outlook, Windows Live Mail) ?

 ALex.

&lt;P&gt;I changed user&#039;s password, then i found a secondo user with account hacked and i changed his password too ...&lt;/P&gt; &lt;P&gt;I woluld know how this&amp;nbsp;is possible ...&amp;nbsp;perhaps exist a family of &lt;SPAN id=result_box lang=en class=short_text closure_uid_1jgwwy=&quot;119&quot; a=&quot;undefined&quot; c=&quot;4&quot;&gt;&lt;SPAN class=hps closure_uid_1jgwwy=&quot;227&quot;&gt;trojans&lt;/SPAN&gt; &lt;SPAN class=hps closure_uid_1jgwwy=&quot;228&quot;&gt;that can&lt;/SPAN&gt; &lt;SPAN class=hps closure_uid_1jgwwy=&quot;229&quot;&gt;steal users&#039; password stored in the mail client (Outlook, Windows Live Mail) ?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt; &lt;P&gt;&lt;SPAN lang=en class=short_text closure_uid_1jgwwy=&quot;119&quot; a=&quot;undefined&quot; c=&quot;4&quot;&gt;&lt;SPAN class=hps closure_uid_1jgwwy=&quot;229&quot;&gt;&amp;nbsp;ALex.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;

[quote user="alexbromo"]I woluld know how this is possible ... perhaps exist a family of trojans that can steal users' password stored in the mail client (Outlook, Windows Live Mail) ?[/quote]

Many options:

  • very simple password
  • user takes same password elsewhere
  • pishing
  • Trojan or keyboard-Logger on PC of user
  • brute force: check logs of all your servies accessable from internet: SMTP, FTP, HTTP ...
    (sometimes my FTP-Logs looking very interesting ... therefore no admin account is allowed to use FTP ;-)
  • Sniffing the internet (or even your internal network): all your servies where passwords are send via net should be encryted (i.e. StartTLS or SSL with all mailservices).
  • ...

Getting a network secure isn't that simple ... :-(

 

&lt;p&gt;[quote user=&quot;alexbromo&quot;]I woluld know how this&amp;nbsp;is possible ...&amp;nbsp;perhaps exist a family of &lt;span id=&quot;result_box&quot; class=&quot;short_text&quot; closure_uid_1jgwwy=&quot;119&quot; a=&quot;undefined&quot; c=&quot;4&quot; lang=&quot;en&quot;&gt;&lt;span class=&quot;hps&quot; closure_uid_1jgwwy=&quot;227&quot;&gt;trojans&lt;/span&gt; &lt;span class=&quot;hps&quot; closure_uid_1jgwwy=&quot;228&quot;&gt;that can&lt;/span&gt; &lt;span class=&quot;hps&quot; closure_uid_1jgwwy=&quot;229&quot;&gt;steal users&#039; password stored in the mail client (Outlook, Windows Live Mail) ?&lt;/span&gt;&lt;/span&gt;[/quote]&lt;/p&gt;&lt;p&gt;Many options:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;very simple password&lt;/li&gt;&lt;li&gt;user takes same password elsewhere &lt;/li&gt;&lt;li&gt;pishing &lt;/li&gt;&lt;li&gt;Trojan or keyboard-Logger on PC of user&lt;/li&gt;&lt;li&gt;brute force: check logs of all your servies accessable from internet: SMTP, FTP, HTTP ... (sometimes my FTP-Logs looking very interesting ... therefore no admin account is allowed to use FTP ;-)&lt;/li&gt;&lt;li&gt;Sniffing the internet (or even your internal network): all your servies where passwords are send via net should be encryted (i.e. StartTLS or SSL with all mailservices).&lt;/li&gt;&lt;li&gt;...&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Getting a network secure isn&#039;t that simple ... :-(&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;

Yes, it's true ... getting networks secure is a real challenge. :(

However, after two password change the situation seems to be calmed (cross fingers).

Thank you guys, today you have helped me incredibly and i learned a lot,

ALex.

&lt;p&gt;Yes, it&#039;s true ... getting networks secure is a real challenge. :(&lt;/p&gt;&lt;p&gt;However, after two password change the situation seems to be calmed (cross fingers).&lt;/p&gt;&lt;p&gt;Thank you guys, today you have helped me incredibly and i learned a lot, &lt;/p&gt;&lt;p&gt;ALex.&lt;/p&gt;
live preview
enter atleast 10 characters
WARNING: You mentioned %MENTIONS%, but they cannot see this message and will not be notified
Saving...
Saved
With selected deselect posts show selected posts
All posts under this topic will be deleted ?
Pending draft ... Click to resume editing
Discard draft