Zer0 G -> Spam Internal (18.May2011 8:25:04 AM)

Question, I need a way to throttle messages from internal users. Recently one of our users clicked on a link and entered their username and password onto a website. Our domain got blacklisted within the hour due to the 100k spam from the compromised account. I am just trying to avoid another issue like that in the future. So far all I am able to do is disable owa for the user and change the AD password bounce IIS and kill the NDRs.

Anybody have any tips for when a user account is compromised and sending spam? Are there any features I am looking over in the EMC?

