SMTP hacked by spammer using base64 encoding to authenticate

Posted by Throlkim on Server Fault See other posts from Server Fault or by Throlkim
Published on 2010-05-05T08:58:22Z Indexed on 2010/05/05 9:08 UTC
Read the original article Hit count: 282

Filed under:
|
|
|
|

Over the past day we've detected someone from China using our server to send spam email. It's very likely that he's using a weak username/password to access our SMTP server, but the problem is that he appears to be using base64 encoding to prevent us from finding out which account he's using. Here's an example from the maillog:

May  5 05:52:15 195396-app3 smtp_auth: SMTP connect from (null)@193.14.55.59.broad.gz.jx.dynamic.163data.com.cn [59.55.14.193]
May  5 05:52:15 195396-app3 smtp_auth: smtp_auth: SMTP user info : logged in from (null)@193.14.55.59.broad.gz.jx.dynamic.163data.com.cn [59.55.14.193]

Is there any way to detect which account it is that he's using?

© Server Fault or respective owner

Related posts about hacking

Related posts about smtp