OK, so you suspect that somewhere on your network there is a compromised pc that is acting as a spam server. What tools can you use to locate the rouge spammer? We are using MS Exchange 2003 all users are running Outlook for e-mail client.
I have tried using packet capturing like Wireshark (Ethereal). I can identify out going as SMTP mail, but it has a <> sender field. I have tried to find relevant packets going to the Exchange server to determine what pc sent the message. But it is impossible to read packets going to the server, obviously not plain text.
Has anyone else been successful in flushing out a rouge spam server and what tools did you use?