Click here to get back home

SMTPSVC events

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
SMTPSVC events aboni 06-13-2006
Posted by aboni on June 13, 2006, 9:11 am
Please log in for more thread options
Hi!

I have a SMTP service running in Windows Server 2003 R2 and in the events
log is so mutch SMTPSVC entries. I put a screen of my log in the link:
http://200.162.106.90/windowsevent.jpg.

The messages are like below:

[Example1]
Message delivery to the host '10.23.42.11' failed while delivering to the
remote domain '006.com' for the following reason: The remote server did not
respond to a connection attempt.

[Example2]
Message delivery to the remote domain 'giut.com' failed for the following
reason: Unable to bind to the destination server in DNS.

I have sure that this mail's aren't sent by my users. The entries occur in
the weekends also, when nobody is using this service.

Thanks for any help,
Andrew



Posted by S. Pidgorny on June 14, 2006, 6:33 am
Please log in for more thread options
Maybe somebody does. Enable authentication and logging to collect more
information about the suspicious activities - that may help you discovering
a rogue client, or a network backdoor.

--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-


> Hi!
>
> I have a SMTP service running in Windows Server 2003 R2 and in the events
> log is so mutch SMTPSVC entries. I put a screen of my log in the link:
> http://200.162.106.90/windowsevent.jpg.
>
> The messages are like below:
>
> [Example1]
> Message delivery to the host '10.23.42.11' failed while delivering to the
> remote domain '006.com' for the following reason: The remote server did
> not respond to a connection attempt.
>
> [Example2]
> Message delivery to the remote domain 'giut.com' failed for the following
> reason: Unable to bind to the destination server in DNS.
>
> I have sure that this mail's aren't sent by my users. The entries occur in
> the weekends also, when nobody is using this service.
>
> Thanks for any help,
> Andrew
>
>



Posted by aboni on June 14, 2006, 8:27 am
Please log in for more thread options
Thanks for reply!

I will investigate more!

Thanks for help,
Andrew

> Maybe somebody does. Enable authentication and logging to collect more
> information about the suspicious activities - that may help you
> discovering a rogue client, or a network backdoor.
>
> --
> Svyatoslav Pidgorny, MS MVP - Security, MCSE
> -= F1 is the key =-
>
>
>> Hi!
>>
>> I have a SMTP service running in Windows Server 2003 R2 and in the events
>> log is so mutch SMTPSVC entries. I put a screen of my log in the link:
>> http://200.162.106.90/windowsevent.jpg.
>>
>> The messages are like below:
>>
>> [Example1]
>> Message delivery to the host '10.23.42.11' failed while delivering to the
>> remote domain '006.com' for the following reason: The remote server did
>> not respond to a connection attempt.
>>
>> [Example2]
>> Message delivery to the remote domain 'giut.com' failed for the following
>> reason: Unable to bind to the destination server in DNS.
>>
>> I have sure that this mail's aren't sent by my users. The entries occur
>> in the weekends also, when nobody is using this service.
>>
>> Thanks for any help,
>> Andrew
>>
>>
>
>



Similar ThreadsPosted
Auditing Security Events May 10, 2007, 1:54 am
Follow-up to Empty 529 Events in Security Log July 27, 2006, 12:02 pm
How to store windows events log in remote server July 31, 2005, 6:44 pm
All I want to do is audit "delete" events, but log gets massive: how to do effiecntly? November 3, 2005, 8:59 am
Security Log - Events 680, 529 and 675 for NT AUTHORITY\SYSTEM every two minutes February 5, 2006, 11:50 am
Multiple 538 and 540 ID's in 2003 server Security Events Log? August 23, 2006, 12:58 am
KB 925902 causes SceCli 1202 warning events every 5 minutes April 19, 2007, 12:31 pm
audit logon/logoff events on terminal server July 18, 2007, 10:29 am
Logon/Logoff Events in Local Security Log of Terminal Server July 20, 2007, 2:39 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap