Open Mail Relay

John Levine johnl at
Mon Aug 16 17:28:16 UTC 2010

>> Assume, as Mr. Bonomi suggests, that some bad guy has installed some
>type of additional mailer on the machine or another machine that's
>allowed to relay mail.  How would I go about locating that other mailer?

Another popular hack is uploading a PHP script using bugs in a CMS or wiki.

Once you have a message with accurate timestamps in the headers, check the
web logs at those times, too.


