From owner-freebsd-questions@FreeBSD.ORG Sun Aug 15 15:38:32 2010 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 63122106566C for ; Sun, 15 Aug 2010 15:38:32 +0000 (UTC) (envelope-from ryan.coleman@cwis.biz) Received: from qmta14.emeryville.ca.mail.comcast.net (qmta14.emeryville.ca.mail.comcast.net [76.96.27.212]) by mx1.freebsd.org (Postfix) with ESMTP id 4ABD78FC1D for ; Sun, 15 Aug 2010 15:38:31 +0000 (UTC) Received: from omta02.emeryville.ca.mail.comcast.net ([76.96.30.19]) by qmta14.emeryville.ca.mail.comcast.net with comcast id ueg41e0080QkzPwAEfeXTp; Sun, 15 Aug 2010 15:38:31 +0000 Received: from [10.0.1.9] ([76.113.183.74]) by omta02.emeryville.ca.mail.comcast.net with comcast id ufeV1e0031cjQTw8NfeWyf; Sun, 15 Aug 2010 15:38:31 +0000 Mime-Version: 1.0 (Apple Message framework v1081) Content-Type: text/plain; charset=us-ascii From: Ryan Coleman In-Reply-To: <20100815152031.D72621065675@hub.freebsd.org> Date: Sun, 15 Aug 2010 10:38:29 -0500 Content-Transfer-Encoding: quoted-printable Message-Id: References: <201008142113.o7ELDsin018314@mail.r-bonomi.com> <20100815152031.D72621065675@hub.freebsd.org> To: peter@vfemail.net X-Mailer: Apple Mail (2.1081) Cc: FreeBSD Questions Subject: Re: Open Mail Relay X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 15 Aug 2010 15:38:32 -0000 On Aug 15, 2010, at 6:57 AM, peter@vfemail.net wrote: > I've requested copies of the offensive messages, and I'm hopeful the = complainer will send me copies. I believe I have control over the = majordomo lists -- postings are restricted to list members, postings are = monitored, and many lists are moderated. =20 >=20 > Assume, as Mr. Bonomi suggests, that some bad guy has installed some = type of additional mailer on the machine or another machine that's = allowed to relay mail. How would I go about locating that other mailer? = =20 In my experiences if they were relaying through your machine you'd still = see it on the logs. Look for the time/date of the emails you get from = the complainant and see if anything matches up. Then use the IPs to = track down who might be doing it. A little detective work can go a long way. -- Ryan=