<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to track spammer targets? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/how-to-track-spammer-targets/m-p/195786#M435950</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;More on this problem... I suspect one of our users may be sending spam; we detect high volumes of traffic in protocols smtp and pop3 by the use of NBAR. Now, unless someone complains about being targets from SPAM from us, and that complain actually reaches us (cursing aloud is not enough!) I may not be aware our network is being used for spamming. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I want is to track to which IPs this user is sending most of his traffic and then I *proactively* would contact their network admins and ask them *basically* "Do you hate me? Sorry.. it's us but it is not me!", and then have arguments to ask our user to stop his behaviour.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any other way embedded in the router to achieve this? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Already we are looking into installing a sniffer and take it from there... but hoped the router had a way to do it.&lt;/P&gt;&lt;P&gt;- Adrian&lt;/P&gt;&lt;P&gt;(still hopeful)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 03 Sep 2003 16:26:29 GMT</pubDate>
    <dc:creator>butanski</dc:creator>
    <dc:date>2003-09-03T16:26:29Z</dc:date>
    <item>
      <title>How to track spammer targets?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-track-spammer-targets/m-p/195784#M435948</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Is there a way to identify what addresses is a spammer attacking? Very much like NBAR that reports protocols accounting by interface, we need to be able to tell a list of ip addresses (or networks) an interface is reaching.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;- Adrian&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 14:27:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-track-spammer-targets/m-p/195784#M435948</guid>
      <dc:creator>butanski</dc:creator>
      <dc:date>2019-03-10T14:27:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to track spammer targets?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-track-spammer-targets/m-p/195785#M435949</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are trying to use your router to block the spamming you are receiving, do a show ip packet detail and pick through it to find the ports. Look at every one of your ip addresses, check them against the ones in his email server to find out which ones are spam. If you are using caching, please see bug CSCdx05705.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Sep 2003 15:18:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-track-spammer-targets/m-p/195785#M435949</guid>
      <dc:creator>drolemc</dc:creator>
      <dc:date>2003-09-03T15:18:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to track spammer targets?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-track-spammer-targets/m-p/195786#M435950</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;More on this problem... I suspect one of our users may be sending spam; we detect high volumes of traffic in protocols smtp and pop3 by the use of NBAR. Now, unless someone complains about being targets from SPAM from us, and that complain actually reaches us (cursing aloud is not enough!) I may not be aware our network is being used for spamming. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I want is to track to which IPs this user is sending most of his traffic and then I *proactively* would contact their network admins and ask them *basically* "Do you hate me? Sorry.. it's us but it is not me!", and then have arguments to ask our user to stop his behaviour.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any other way embedded in the router to achieve this? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Already we are looking into installing a sniffer and take it from there... but hoped the router had a way to do it.&lt;/P&gt;&lt;P&gt;- Adrian&lt;/P&gt;&lt;P&gt;(still hopeful)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Sep 2003 16:26:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-track-spammer-targets/m-p/195786#M435950</guid>
      <dc:creator>butanski</dc:creator>
      <dc:date>2003-09-03T16:26:29Z</dc:date>
    </item>
  </channel>
</rss>

