Facebook   Twitter    e-mail newsletter    YouTube    RSS Feed    Android App    iPhone and iPad App     BlackBerry App    


Page 1 of 3 1 23 LastLast
Results 1 to 15 of 39

Thread: &;$/&$)&/$)&$? Spammers

  1. #1
    SmoothSupport The_Librarian's Avatar
    Join Date
    Apr 2005
    Location
    Lothlorien
    Posts
    73,963
    Blog Entries
    19

    Default &;$/&$)&/$)&$? Spammers

    So I got a complaint from our ISP that we're sending out spam. Logged in to the Exchange server, and took a shufty at the mail queues via the exchange manager.

    700+ queues of spam.

    Cleaned up the active queues, and a bit more.

    Then I went off to have a shufty at the log files. The log file for Tuesday was over 1Gb in size, and the log for Wednesday was over 500Mb in size. i kid you not.

    Word, Notepad and Wordpad all balked at opening those log files.

    So I copied them over to a Linux PC and took a shufty at these.

    Found out that the spammer was using a static IP (hence blacklisting not working).... In a fit of rage I entered both his domain and static IP in the 'deny' lists.

    Will post pics later up on what and where though.

    Today I will be implementing a Linux mail filtering solution, to stop pesky buggers like this... this... ****** from spamming us again. And I'll contact Spamhaus to get that IP listed.

    Can also be somebody else's email server got compromised though....
    Christ-mass is NOT for Christians. Jeremiah 10.
    Is the 10 Commandments for Christians?

    Saturday is the Seventh day, Sunday is the first day.

    Shmiert Shpammer

  2. #2

    Default

    Your exchange is misconfigured

    I suspect it's an open relay,if you send me the IP I can confirm and tell you how to lock it down
    www.domaincheap.co.za
    50% off 1st month Afrihost Uncapped here - No contracts

  3. #3
    SmoothSupport The_Librarian's Avatar
    Join Date
    Apr 2005
    Location
    Lothlorien
    Posts
    73,963
    Blog Entries
    19

    Default

    Quote Originally Posted by PsyWulf View Post
    Your exchange is misconfigured

    I suspect it's an open relay,if you send me the IP I can confirm and tell you how to lock it down
    Nope.

    The chappie who installed it, did indeed misconfigured it, and it was open. Googled for it, and locked it down pronto.

    I PM'd you, if you ca just check and make sure?

    Thanks!
    Christ-mass is NOT for Christians. Jeremiah 10.
    Is the 10 Commandments for Christians?

    Saturday is the Seventh day, Sunday is the first day.

    Shmiert Shpammer

  4. #4
    Master shakes1's Avatar
    Join Date
    Jun 2010
    Location
    Lost and Confused...
    Posts
    977

    Default

    A quick question, how did the culprit discover your mail server was an open relay? Is it perhaps a high impact domain, so everyone knows about it... Thinking out loud...

    Mind sharing which ISP picked up this problem?

  5. #5

    Default

    It's easy enough to script a test connection to port25 in an IP range and log any responses that aren't deny for later use

    Will test it now libs
    www.domaincheap.co.za
    50% off 1st month Afrihost Uncapped here - No contracts

  6. #6

    Default

    Yep it's closed down now

    There is one more thing you should check too,and that's to deny sending to any addresses not listed in Active Directory,prevents those random mail bombers from hitting your internal mail stores
    www.domaincheap.co.za
    50% off 1st month Afrihost Uncapped here - No contracts

  7. #7
    Master shakes1's Avatar
    Join Date
    Jun 2010
    Location
    Lost and Confused...
    Posts
    977

    Default

    Oh high and mighty scripter... Please point me in the right direction so that I could learn some of your ways...



    *darn, still can't quote on mobile*

  8. #8

    Default

    Lol,no,it's something that could be abused :P

    Short answer is to generate a list of IPs in a range,usually by pinging and entire range and only logging responses,many ways to do this,and this logged list would be used for the 2nd part,connecting to port 25,sending a HELO,and waiting for a success response for RCPT TO: "external address" which you'd log
    www.domaincheap.co.za
    50% off 1st month Afrihost Uncapped here - No contracts

  9. #9
    SmoothSupport The_Librarian's Avatar
    Join Date
    Apr 2005
    Location
    Lothlorien
    Posts
    73,963
    Blog Entries
    19

    Default

    Quote Originally Posted by PsyWulf View Post
    Yep it's closed down now

    There is one more thing you should check too,and that's to deny sending to any addresses not listed in Active Directory,prevents those random mail bombers from hitting your internal mail stores
    Thanks, will take a shufty at that. But I think it's already enabled, won't hurt to make double sure.

    Cleaned out the last bits of "retry" spam queues. So far so good.

    Log files indicate that said spammer did try to connect and send spam, but instead got a .!..

    The ISP is Internet Solutions. I'm glad it was them - and not Spamhaus...
    Christ-mass is NOT for Christians. Jeremiah 10.
    Is the 10 Commandments for Christians?

    Saturday is the Seventh day, Sunday is the first day.

    Shmiert Shpammer

  10. #10
    SmoothSupport The_Librarian's Avatar
    Join Date
    Apr 2005
    Location
    Lothlorien
    Posts
    73,963
    Blog Entries
    19

    Default

    Quote Originally Posted by PsyWulf View Post
    Lol,no,it's something that could be abused :P

    Short answer is to generate a list of IPs in a range,usually by pinging and entire range and only logging responses,many ways to do this,and this logged list would be used for the 2nd part,connecting to port 25,sending a HELO,and waiting for a success response for RCPT TO: "external address" which you'd log
    Or probing for open port 25's on an IP range, log these, then spam these with mail hoping something goes through...

    Crafty dang spammers
    Christ-mass is NOT for Christians. Jeremiah 10.
    Is the 10 Commandments for Christians?

    Saturday is the Seventh day, Sunday is the first day.

    Shmiert Shpammer

  11. #11
    SmoothSupport The_Librarian's Avatar
    Join Date
    Apr 2005
    Location
    Lothlorien
    Posts
    73,963
    Blog Entries
    19

    Default

    By the by, my firewall is locked down tight on outgoing ports. Nobody can smtp to the outside, only the email server can. Which means they have to smtp to the email server in order to send their message(s)...

    Yonkers ago I got blacklisted What happened was that somebody got a spam mail with "Free games!!!" as the subject, forwarded it to his buddies at work, opened the attachment, and got turned into a spambot Now I totally deny any outgoing port 25 request - if they need to check their gmail, they can use a web browser. So sorry, but I'm not gonna fall for that thing again.

    Took a day or two for me to clean up the mess. I ***** him out good and proper.
    Christ-mass is NOT for Christians. Jeremiah 10.
    Is the 10 Commandments for Christians?

    Saturday is the Seventh day, Sunday is the first day.

    Shmiert Shpammer

  12. #12

    Default

    Quote Originally Posted by The_Librarian View Post
    Word, Notepad and Wordpad all balked at opening those log files.

    So I copied them over to a Linux PC and took a shufty at these.
    Ummmm, you use windows and you use those silly apps? Why haven't you installed Notepad++ ?

  13. #13

    Default

    Quote Originally Posted by Chunkyfeather View Post
    Ummmm, you use windows and you use those silly apps? Why haven't you installed Notepad++ ?
    Or try MetaPad, works great with huge files.

    Glad you found the spam and shut it down quickly, that could have been really bad for you if you got blacklisted.

  14. #14

    Default

    Actually your SMTP is listed on 2 lists at the moment libs :P
    www.domaincheap.co.za
    50% off 1st month Afrihost Uncapped here - No contracts

  15. #15
    SmoothSupport The_Librarian's Avatar
    Join Date
    Apr 2005
    Location
    Lothlorien
    Posts
    73,963
    Blog Entries
    19

    Default

    Quote Originally Posted by PsyWulf View Post
    Actually your SMTP is listed on 2 lists at the moment libs :P
    MEH

    Which lists?
    Christ-mass is NOT for Christians. Jeremiah 10.
    Is the 10 Commandments for Christians?

    Saturday is the Seventh day, Sunday is the first day.

    Shmiert Shpammer

Page 1 of 3 1 23 LastLast

Bookmarks

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •