The UNIX and Linux Forums  
Hello and Welcome from United States to the UNIX and Linux Forums! Thank You for Visiting and Joining Our Global Community.

Go Back   The UNIX and Linux Forums > Special Forums > Security
.
google unix.com



Security Discuss UNIX and Linux computer and network security, cybersecurity, cyberattacks, IT security, CISSP, OWASP and more.

More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
postfix sending but not recieving mcraul UNIX for Advanced & Expert Users 1 06-10-2008 07:16 PM
Mail recieving problem pankajkrmishra Shell Programming and Scripting 2 08-09-2006 03:58 AM
Where is "SPAM" coming from? bakunin What's on Your Mind? 1 12-05-2005 12:26 AM
mailx undeliverable starla0316 Shell Programming and Scripting 0 05-31-2005 10:37 PM
Why am I not recieving email notification? Kelam_Magnus Post Here to Contact Site Administrators and Moderators 6 09-03-2002 10:01 PM

Closed Thread
English Japanese Spanish French German Portuguese Italian Dutch Swedish Russian Norwegian Hungarian Hebrew Danish
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
  #1 (permalink)  
Old 12-03-2008
edzillion edzillion is offline
Registered User
  
 

Join Date: Sep 2008
Posts: 8
recieving undeliverable reciepts of spam mails that seem to be coming from my domain

Hi
I am getting undeliverable reciepts for what look like spam emails coming from my domain. Here is an example:

Your message did not reach some or all of the intended recipients.
Subject:Attack your baby, she wants
Sent:02/12/2008 01:45

The following recipient(s) cannot be reached:
blah@blah.com on 02/12/2008 01:45
The message reached the recipient's e-mail system, but delivery was refused. Attempt to resend the message. If it still fails, contact your system administrator.
< server.server.com #5.2.0 SMTP; 550 ######## SPAM EMAIL NOT ACCEPTED ########>

The server listed at the bottom is listed second on the list of mx records for the domain the emails seem to be coming from.
What should I do to get rid of these? Should I be worried etc.
  #2 (permalink)  
Old 12-05-2008
otheus's Avatar
otheus otheus is offline Forum Staff  
Moderator ala Mode
  
 

Join Date: Feb 2007
Location: Innsbruck, Austria
Posts: 1,864
You might not need to worry. These messages might be simple forgeries using a From address that has your domain in it. Check to see if the messages are actually being SENT from your server. Then you have to worry.
  #3 (permalink)  
Old 12-05-2008
edzillion edzillion is offline
Registered User
  
 

Join Date: Sep 2008
Posts: 8
Yeah I looked at the message headers and they arent being sent by us (phew!) - the word seems to be 'sit it out' but it realy makes me angry since we are a business that depends on email, and being blacklisted would be apolcalyptic....

Out of interest, why do mail servers relay mail from ISPs that allow spammers? Surely all the spam in the world could be solved by a law that says:

It is illegal for ISPs to allow spammers on their network, or recieve mail from an ISP that allows spammers.

?
  #4 (permalink)  
Old 12-05-2008
otheus's Avatar
otheus otheus is offline Forum Staff  
Moderator ala Mode
  
 

Join Date: Feb 2007
Location: Innsbruck, Austria
Posts: 1,864
Ahem. Welcome to the club.

There are a couple of blacklisting sites. Scan them regularly to see if your host is blacklisted. If it is, appeal immediately.

As far as your legal question... there are some laws that say that, but who's going to enforce indonesian hackers spamming Canadian businesses using a German domain?
  #5 (permalink)  
Old 04-17-2009
soted soted is offline
Registered User
  
 

Join Date: Apr 2009
Posts: 6
edzillion:
Quote:
What should I do to get rid of these? Should I be worried etc.
I know this post is quite old, but just so you know, the spammer most likely forged its reply address using an email address from your domain. Spammers forge reply addresses of legitimate email addresses all the time. Usually they move on to others and you have to wait it out. Hopefully by now you no longer have this issue. Though I do not know if they are targeting an actual email address of yours or sending to a "dummy" email address at your domain: one thing that might help is if you disable your catch all and send the email sent to non-existing accounts to dev/null.

edzillion:
Quote:
Out of interest, why do mail servers relay mail from ISPs that allow spammers? Surely all the spam in the world could be solved by a law that says:

It is illegal for ISPs to allow spammers on their network, or recieve mail from an ISP that allows spammers.
Another thing now is spam has moved to botnets, so spam is being sent from so many originating IPs that blocklisting them all is nearly impossible, so this is why mailservers will accept some mail from seemingly spammy ISPs. Sometimes there are blacklists (BLs) that get too blacklist happy and end up blocking huge portions of the Internet, say blocking a /24 over a few spam complaints. A /24 range of IP addresses is 256, so innocent users are in that block. Sometimes it has to be done so that an ISP will even notice, so you always have two sides of the story in minimizing spam. When it gets that unreasonable, mail admins move onto other blacklists to use. Yes, some ISPs definitely do not take care of their spamming issues enough, while others are more responsible. Some BLs I recommend are Spamhaus and CBL.

Spam is considered illegal in many countries around the world, however, catching and prosecuting spammers is extremely difficult, especially since some spammers hide in countries that have government officials who choose not to cooperate with international organizations such as Interpol. Better coordination is taking place, but it is very difficult to prosecute say a Latvian-based spam group that spams shucking pharma from botnets in Brazil to recipients in France.

Last edited by soted; 04-17-2009 at 03:46 AM..
Sponsored Links
Closed Thread

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -4. The time now is 08:17 PM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited. Language translation by Google.
vBCredits v1.4 Copyright ©2007 - 2008, PixelFX Studios
The UNIX and Linux Forums Content Copyright ©1993-2009. All Rights Reserved.Ad Management by RedTyger

Content Relevant URLs by vBSEO 3.2.0