Security Basics mailing list archives

Re: Email Monitoring


From: "Chris Berry" <compjma () hotmail com>
Date: Tue, 06 May 2003 11:57:05 -0700

From: <jimmy2600 () hushmail com>
I've been asked by a company to set up some kind of email monitoring
software, what they want is to record (save the full email and any attachments)
mail which is sent to certain domains i.e. competitors, some kind of
alert after such a event should also be sent to a number of senior executives
in the co.

The mail server is Exchange and they do not want to spend money on software.
At present all inbound mail is scanned by a SMTP proxy that carries out
content and spam checking. It’s a beefy Redhat8.0 box using Spamassasin
and Mimedefang.

What I aim to do is deliver all out bound mail through the proxy and
:

1. Hopefully find some kind of open source implementation that can do
what I want.

2. Hack some kind of filter with Perl.

The second option really isn’t a good one as my programming skills lead
a lot to be desired.

Has anyone got any input on this, am I going down the wrong path or maybe
someone has implemented something similiar?

I'm not an Exchange expert but what about this:

http://www.msexchange.org/tutorials/MF011.html

Another solution would be a second email server that you would forward all mail through. While forwarding, the second mail server would make a copy and store that locally. I know qmail can do this for sure, and I'd be surprised if you couldn't also do it with postfix, etc.

Chris Berry
compjma () hotmail com
Systems Administrator
JM Associates

"This email is ROT26 encrypted, by reading it you are in violation of the DMCA, and should turn yourself in to the authorities immediately."

_________________________________________________________________
The new MSN 8: smart spam protection and 2 months FREE* http://join.msn.com/?page=features/junkmail


---------------------------------------------------------------------------
FastTrain has your solution for a great CISSP Boot Camp. The industry's most recognized corporate security certification track, provides a comprehensive prospectus based upon the core principle concepts of security. This ALL INCLUSIVE curriculum utilizes lectures, case studies and true hands-on utilization of pertinent security tools. For a limited time you can enter for a chance to win one of the latest technological innovations, the SEGWAY HT. Log onto http://www.securityfocus.com/FastTrain-security-basics ----------------------------------------------------------------------------


Current thread: