Today a friend asked me to look at something strange he found in his logs.
To better understand the situation, I’ll describe his network setup:
He runs a linux server with postfix, spamassassin and clamav antivirus which removes all spam and virusses received from the internet. All legitimate e-mail is then routed to his exchange server. E-mail that is sent by users on his network is relayed back to the linux server and then sent to the destination.
Last week he was checking his mail logs on his linux machine and he noticed his box was receiving e-mail from strange e-mail addresses. He figured: Well, no surprise there: Probably spam messages. Until he looked at the ip address from which it originated: It was the ip address of his own exchange server. First thing he did was doing a full virusscan of his exchange server. Nothing. He tried some spyware scanners, but again: Nothing. So he called me.