Help - Search - Members - Calendar
Full Version: spam relay problem
The Planet Forums > System Administration > HOWTOs
doncamillo
The Planet send me a mail that says:

"It appears that spam is being relayed through your server.; We have attached a complaint complete with headers for your review. Please investigate and resolve this issue."

But i dont have any idea how to invastigate and solve.

Can anyone help me?


And the attached files is :


CODE
From neo1 Wed Nov 12 01:21:50 2008

X-Apparently-To: new.id@sbcglobal.net via 68.142.199.123; Wed, 12 Nov 2008 01:22:01 -0800

X-Originating-IP: [67.18.241.154]

Return-Path: <neneshaw@cox.net>

Authentication-Results: mta153.sbc.mail.mud.yahoo.com from=mailshack.com; domainkeys=neutral (no sig)

Received: from 207.115.20.169 (EHLO flpi129.prodigy.net) (207.115.20.169)

by mta153.sbc.mail.mud.yahoo.com with SMTP; Wed, 12 Nov 2008 01:22:00 -0800

X-Originating-IP: [67.18.241.154]

Received: from kurumsal.interkeyservers.com (soup.capital-today.net [67.18.241.154] (may be forged))

by flpi129.prodigy.net (8.13.8 inb regex/8.13.icon_cool.gif with ESMTP id mAC9LxSH009195;

Wed, 12 Nov 2008 01:21:59 -0800

Received: from [88.226.109.201] (helo=dsl88-226-28105.ttnet.net.tr)

by kurumsal.interkeyservers.com with esmtp (Exim 4.69)

(envelope-from <neneshaw@cox.net>)

id 1L0BvB-0005SF-2M; Wed, 12 Nov 2008 11:21:57 +0200

Received: from [179.175.21.104] (HELO CUPNUWQRI)

by 88.226.109.201 (CommuniGate Pro SMTP 5.0.11)

with SMTP id 39967261 for nett0385@sbcglobal.net; Wed, 12 Nov 2008 11:21:50 +0200

Message-ID: <005801c944a8$1873da50$c96de258@dsl8822628105.ttnet.net.tr>

From: "neo1" <neo1@mailshack.com>

To: <nett0385@sbcglobal.net>, <neums1@sbcglobal.net>, <new.id@sbcglobal.net>,

<nglesner@sbcglobal.net>, <ngmkp@sbcglobal.net>

Subject: Hottest and finest dis{0u nt s for ed preparations

Date: Wed, 12 Nov 2008 11:21:50 +0200

MIME-Version: 1.0

Content-Type: multipart/alternative;

boundary="----=_NextPart_000_0055_01C944B8.DBB986D0"

X-Priority: 3

X-MSMail-Priority: Normal

X-Mailer: Microsoft Outlook Express 6.00.2900.3942

X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3892

X-ACL-Warn: {

X-AntiAbuse: This header was added to track abuse, please include it with any abuse report

X-AntiAbuse: Primary Hostname - kurumsal.interkeyservers.com

X-AntiAbuse: Original Domain - sbcglobal.net

X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]

X-AntiAbuse: Sender Address Domain - cox.net

X-Source:

X-Source-Args:

X-Source-Dir:

Content-Length: 1000





This is a multi-part message in MIME format.



------=_NextPart_000_0055_01C944B8.DBB986D0

Content-Type: text/plain;

charset="us-ascii"

Content-Transfer-Encoding: quoted-printable



ujhd

------=_NextPart_000_0055_01C944B8.DBB986D0

Content-Type: text/html;

charset="us-ascii"

Content-Transfer-Encoding: quoted-printable



<html>

<head>

<style type=3D"text/css"><!-- DIV {margin:0px;} --></style>

</head>

<body>

<br>

<br>

<br>

<br>

<div style=3D"font-family:Tahoma ;font-size:11pt">biceps ski lodge</div>=

<br>

<div style=3D"font-family:Tahoma ;font-size:12pt">turn signal ruminates<=

/div>

<div style=3D"font-family:'Courier New', Courier, mono;font-size:16pt"><=

a href=3D"http://bestphysicianintown.com.es">All kinds of preventive exa=

mination </a></div>

<div style=3D"font-family:Tahoma ;font-size:12pt">beyond minivan inside =

midwife accurately</div>

<br>

<div style=3D"font-family:Tahoma ;font-size:10pt">chic clodhoppers</div>=

</body>

</html>





------=_NextPart_000_0055_01C944B8.DBB986D0--
Catalyst
What kind of server? Is it running a control panel?

It would be easier to track if the bad header wasn't nine days old. You need to look in your maillog for all outgoing mail, and match it up with the secure log to see which account it's sending through.

Since your server uses pop-before-SMTP as authentication (a bad idea), any customer with a Virus who regularly checks their mail can use your server as an open relay.
doncamillo
so whats the solution?
Catalyst
Well, since you didn't say what kind of server and/or control panel, or post any fresher headers, who knows? ;-) Without more information, it's impossible to say.

Investigate your maillogs more thoroughly for clues, get rid of popb4smtp and use Sendmail authentication.
theuruguayan
You seem to have cpanel on the server, i recommend you check the exim_maillog for the email and try to track the source of the email from there.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.