Endpoint Protection

 View Only
  • 1.  Tear Down that Wall

    Posted Oct 01, 2009 01:57 PM
    I am absolutly plagued with russin spam  that is  "sent from" other users in my local domain   

    I need to stop this..please advise


    ddecoursey@eriecountygov.org


  • 2.  RE: Tear Down that Wall

    Posted Oct 01, 2009 02:05 PM
    Hi,

           We would definetly like to help you. However please let us know the version of endpoint and the OS of the server and the client machines and some information about your network architecture so that we can help you.


  • 3.  RE: Tear Down that Wall

    Posted Oct 01, 2009 02:08 PM
    There's no really simple way to deal with spam, Dan.  It's a juggling act...we figure out a new way to stop it, spammers figure out new ways to get around the blocks.

    Realistically speaking, most threats out there today that are used to spam will forge the information about the sender...so if User A gets an email from User B that's spam, it's usually *actually* User C who sent it...investigating User B's computer usually will be fruitless.

    Check your mail server and network logs...you could see one (or more) IP addresses suddenly sending a whole bunch more email traffic...I'd recommend going over those computers looking for abnormalities and work with support to submit any suspicious files.

    This traffic could be coming from outside your network as well.  Work with your network team to see if they can find an increase in incoming email traffic from an external source that could be blocked at the perimeter.

    However, if these logs don't show anything (at least glaringly obvious), you're going to have to do some sleuthing along with some in-depth log analysis with your network team to try to identify the suspicious traffic, trace it back to the source, then focus on that machine (or machines).

    As always, ensure that your AV solution is current with current definitions and regular system scans, as well as ensure that your OS is fully patched.


  • 4.  RE: Tear Down that Wall

    Posted Oct 01, 2009 02:18 PM
    Adding to what chris has written , It is better to have an Anti Spam program like SMSE installed , As SEP will not block SPAM coming into the the network


  • 5.  RE: Tear Down that Wall

    Posted Oct 01, 2009 04:14 PM
    If you are using an antispam product from symantec be sure your own domain is not in the whitelist. This allows spoofed messages to bypass spam filtering.