Date: Thu, 14 Feb 2002 12:06:16 -0500 From: "William J. Petch" <twofour@etherworx.com> To: <freebsd-security@FreeBSD.ORG> Subject: Re: sendmail ; bogus letters Message-ID: <002001c1b579$eab38b70$4e00000a@twofour> References: <Pine.BSF.4.44.0202140740060.52689-100000@R181172.resnet.ucsb.edu> <02021413401002.02159@hercules.avint.net>
next in thread | previous in thread | raw e-mail | index | archive | help
[-- Attachment #1 --] I have been having a spam problem as well. I use ordb.org to block spam, and have noticed a significant decrease in the amount of spam that comes to my server. The problem I am having is I am only getting bounced spam. (And quite a lot of it too.) The original messages are not being relayed, or even touching my server. I have a couple of excerpts of some email headers here... Our mail server's name is mail.etherworx.com, and our server's class C is 216.58.72.xx. ***** Received: from mail.etherworx.com (210.42.64.33 [210.42.64.33]) by mailsrv.hbeeh.edu.cn with SMTP (Microsoft Exchange Internet Mail Service Version 5.5.1960.3) ***** Received: from mail.etherworx.com (61.129.53.123 [61.129.53.123]) by mail.ecepdi.stn.sh.cn with SMTP (Microsoft Exchange Internet Mail Service Version 5.5.1960.3) ***** These messages are being sent as Mark.Cella@etherlinx.ca (A domain that is hosted on my server.) Clearly, these emails are not being routed through my servers. However, whenever these spam mails bounce, they are coming back to mail.etherworx.com. I have no idea whatsoever as to how I can stop these... Anybody??? William J. Petch System Administrator EtherworX, Inc. ----- Original Message ----- From: "Graham Rose" <graham@avint.net> To: <freebsd-security@FreeBSD.ORG> Sent: Thursday, February 14, 2002 12:05 PM Subject: Re: sendmail ; bogus letters > Add entries for the Open Relay Database (www.ordb.org & > www.ordb.org/faq/#sendmail) and spamcop.net (www.spamcop.net) > Configuring your mail server to use these lists of known spammers will block > most spam. I've noticed a 10 fold decrease on my mail server, with thousands of > spam blocked each day. > Note: Setup instructions vary depending on the version of sendmail you run. See > above urls for details. > > -- > Graham Rose > Network Administrator > Avalon InterConnect & Infotech Canada > graham@infotechcanada.com > graham@avint.net > http://www.avint.net > http://www.infotechcanada.com > > > > On Thu, 14 Feb 2002, Dave wrote: > > Some of my accounts are getting some spam (what else is new on the > > internet?). However, the "from" addresses of these letters are not even > > valid (as is with a lot of spam). In a couple of cases they are, but I > > question the letter actually came from the sender listed. > > > > Is there something I can do in the sendmail.cf file or other configuration > > change to drop these kinds of letters? Other solutions? > > > > I've thought of denying messages from free mail sites, but I imagine some > > spam is from elsewhere. I would think it is possible to ditch bulkmail, I > > know that yahoo.com has a bulkmail folder -- and I heard yahoo runs > > FreeBSD too :) How are the letters discriminated from eachother as a bulk > > versus a possible real one? > > > > > > To Unsubscribe: send mail to majordomo@FreeBSD.org > > with "unsubscribe freebsd-security" in the body of the message > > To Unsubscribe: send mail to majordomo@FreeBSD.org > with "unsubscribe freebsd-security" in the body of the message > [-- Attachment #2 --] 0 *H 010 + 0 *H 000 *H 010 UZA10UWestern Cape10U Cape Town10 U Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.300 020117033759Z 030117033759Z0G10UThawte Freemail Member1$0" *H twofour@etherworx.com00 *H 0 _[llED3Og Vd3!yAT_I6VI㾞OJӔSͦ-1 H7A;%߰;rȲL.#˳'ATg&Sk 2000 U0twofour@etherworx.com0U0 0 *H 5mݤ] |\3eMR;r[.4źSz#?2eOL]@]0~̭R]$UszBmDԐ.#U( dǪ|3xC0-0 0 *H 010 UZA10UWestern Cape10U Cape Town10U Thawte Consulting1(0&UCertification Services Division1$0"UThawte Personal Freemail CA1+0) *H personal-freemail@thawte.com0 960101000000Z 201231235959Z010 UZA10UWestern Cape10U Cape Town10U Thawte Consulting1(0&UCertification Services Division1$0"UThawte Personal Freemail CA1+0) *H personal-freemail@thawte.com00 *H 0 id[qGQr^}- {߅%u(t:B,c'{K~ݹΖdnD|Mq@8 x^^v]nz|KU)&j8$jDZڣyZ 00U00 *H ~Ngb*M`o`Xa&R5\0JbB#dG)ߝ^l`q\yn G (|_#& sC%/uQkw080fErtcvE.0 *H 010 UZA10UWestern Cape10U Cape Town10U Thawte Consulting1(0&UCertification Services Division1$0"UThawte Personal Freemail CA1+0) *H personal-freemail@thawte.com0 000830000000Z 040827235959Z010 UZA10UWestern Cape10U Cape Town10 U Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.3000 *H 0 32c %E>nx'gڈD)c5*mp<ܮto034qmOe KaU5u'rװ|CBPQ<9TIf - ki N0L0)U"0 010UPrivateLabel1-2970U0 0U0 *H 1KG]qSl]y=&b""I'{9$ *8PUl LGlX1B li+@]jy.%݊ Z<D&iHΥbb100010 UZA10UWestern Cape10U Cape Town10 U Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.300 + 0 *H 1 *H 0 *H 1 020214170616Z0# *H 1 Y?2<D0[ *H 1N0L0 *H 0*H 0 *H @0+0 *H (0+0 *H ۛ1 \veޏkaW,ĚoH띳CL%V24E5nmYv%ȵ _>}v }EZa]35m#Qբk
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?002001c1b579$eab38b70$4e00000a>
