sebas
Basic Pleskian
We are getting tons of spam mail.
I know our server is configured so that relaying is closed and authorization is required to send mail. But they are using a sneaky trick to place the mail in the queue because as long as I can tell they are not using an account to authorize but they are using a domain that is hosted on our server.
Here is a bit from /var/log/messages:
Aug 17 12:03:12 canada7 xinetd[1429]: START: smtp pid=11924 from=::ffff:187.162.75.104
Aug 17 12:03:19 canada7 xinetd[1429]: START: smtp pid=13837 from=::ffff:171.99.143.254
Aug 17 12:03:22 canada7 xinetd[1429]: START: smtp pid=14423 from=::ffff:190.18.37.99
Aug 17 12:03:23 canada7 xinetd[1429]: EXIT: smtp status=0 pid=11924 duration=11(sec)
Aug 17 12:03:24 canada7 xinetd[1429]: START: submission pid=15369 from=::ffff:173.193.188.226
Aug 17 12:03:24 canada7 xinetd[1429]: EXIT: submission status=0 pid=15369 duration=0(sec)
Aug 17 12:03:25 canada7 xinetd[1429]: START: smtp pid=15513 from=::ffff:212.200.204.103
And here a bit from /usr/local/psa/var/log/maillog:
Aug 17 12:04:30 canada7 qmail-queue-handlers[21097]: Handlers Filter before-queue for qmail started ...
Aug 17 12:04:30 canada7 qmail-queue-handlers[21029]: starter: submitter[21080] exited normally
Aug 17 12:04:30 canada7 qmail-queue-handlers[21038]: starter: submitter[21096] exited normally
Aug 17 12:04:30 canada7 qmail-queue-handlers[21041]: starter: submitter[21078] exited normally
Aug 17 12:04:30 canada7 qmail-queue-handlers[21043]: from=meg@xxxxx.com.mx
Aug 17 12:04:30 canada7 qmail-queue-handlers[21043]: to=adaamalafiisah@yahoo.com
Aug 17 12:04:30 canada7 qmail-queue-handlers[21043]: to=paulkey2013@yahoo.com
Aug 17 12:04:30 canada7 qmail-queue-handlers[21043]: to=ambanicrony@yahoo.com
Aug 17 12:04:30 canada7 qmail-queue-handlers[21043]: handlers_stderr: SKIP
Aug 17 12:04:30 canada7 qmail-queue-handlers[21043]: SKIP during call 'check-quota' handler
Aug 17 12:04:30 canada7 spf filter[21103]: Starting spf filter...
Aug 17 12:04:30 canada7 qmail-queue-handlers[21043]: handlers_stderr: SKIP
Aug 17 12:04:30 canada7 qmail-queue-handlers[21043]: SKIP during call 'spf' handler
Aug 17 12:04:30 canada7 spf filter[21104]: Starting spf filter...
Aug 17 12:04:30 canada7 qmail-queue-handlers[21043]: handlers_stderr: SKIP
Aug 17 12:04:30 canada7 qmail-queue-handlers[21043]: SKIP during call 'spf' handler
Aug 17 12:04:30 canada7 spf filter[21105]: Starting spf filter...
Aug 17 12:04:30 canada7 qmail-queue-handlers[21043]: handlers_stderr: SKIP
Aug 17 12:04:30 canada7 qmail-queue-handlers[21043]: SKIP during call 'spf' handler
Aug 17 12:04:30 canada7 qmail-queue-handlers[21043]: starter: submitter[21106] exited normally
Aug 17 12:04:30 canada7 qmail-queue-handlers[21108]: Handlers Filter before-queue for qmail started ...
Aug 17 12:04:30 canada7 qmail-queue-handlers[21109]: Handlers Filter before-queue for qmail started ...
Aug 17 12:04:30 canada7 qmail-queue-handlers[21063]: from=huj@xxxxx.com.mx
Aug 17 12:04:30 canada7 qmail-queue-handlers[21063]: to=way2zoned44@hotmail.com
Aug 17 12:04:30 canada7 qmail-queue-handlers[21063]: to=asdfga@adsf.com
Aug 17 12:04:30 canada7 qmail-queue-handlers[21063]: to=jimmiew50@gmail.com
Aug 17 12:04:30 canada7 qmail-queue-handlers[21063]: to=slejun@yahoo.com
Aug 17 12:04:30 canada7 qmail-queue-handlers[21063]: to=mnoentil@yahoo.com
Aug 17 12:04:30 canada7 qmail-queue-handlers[21063]: handlers_stderr: SKIP
Aug 17 12:04:30 canada7 qmail-queue-handlers[21063]: SKIP during call 'check-quota' handler
Aug 17 12:04:30 canada7 spf filter[21118]: Starting spf filter...
Aug 17 12:04:30 canada7 qmail-queue-handlers[21063]: handlers_stderr: SKIP
Aug 17 12:04:30 canada7 qmail-queue-handlers[21063]: SKIP during call 'spf' handler
They are sending the mail from a lot of different machines.
I don't know how to stop it and I was wondering if you do.
Here are three samples.
Thanks for your help.
+++++++++++++++++++++++++++++++++++++++++++
Received: (qmail 14598 invoked from network); 17 Aug 2013 11:25:12 -0500
Received: from undef-pesochin-kh.maxnet.ua (HELO pjqwsp) (178.165.84.164)
by canada7.xxxxxxxxxx.com with ESMTPA; 17 Aug 2013 11:25:12 -0500
From: "Xwe Apife" <rugic@xxxxx.com.mx>
To: <tn_sika@yahoo.com>, <mjgman23@googlemail.com>, <smores1998@yahoo.com>, <spacecowboy210@yahoo.com>
Subject:
Date: Sat, 17 Aug 2013 17:16:18 -0700
Mime-Version: 1.0
Content-Type: text/plain; charset=utf-7
zy w
xaruwoq qonoxes kigytoz vup dyd http://www.sogz.ru/movies.htm
poqoz vydu wipoxa
+++++++++++++++++++++++++++++++++++++++++++
Received: (qmail 14983 invoked from network); 17 Aug 2013 11:25:18 -0500
Received: from mm-55-57-120-178.dynamic.pppoe.mgts.by (HELO kabemrylxeb) (178.120.57.55)
by canada7.xxxxxxxxxx.com with ESMTPA; 17 Aug 2013 11:25:17 -0500
Date: Sat, 17 Aug 2013 17:16:23 -0700
From: "Fvuso Jw" <fe@xxxxx.com.mx>
To: <max.rawley@yahoo.com>, <duraens@gmail.com>, <pyronancyrey@aol.com>, <aria_aryan70@yahoo.com>, <crk2430@hotmail.com>, <mg109@gateway.net>, <madison22star@hotmail.com>, <mduong999@aol.com>, <kripal.masughat@gmail.com>, <redneckmatty@comcast.net>
Subject:
Mime-Version: 1.0
Content-Type: text/plain; charset="iso-8859-7"
p me http://www.francoiscavallier.com/video.htm?narybatot r
xes g
+++++++++++++++++++++++++++++++++++++++++++
Received: (qmail 16013 invoked from network); 17 Aug 2013 11:25:32 -0500
Received: from unknown (HELO eunnbyspirt) (109.229.174.161)
by canada7.xxxxxxxxxx.com with ESMTPA; 17 Aug 2013 11:25:31 -0500
Subject:
Date: Sat, 17 Aug 2013 17:16:37 -0700
To: <0billyboy7x@yahoo.com>, <grneyes420@hotmail.com>, <1957210eb@gmail.com>, <burgosjose@ymail.com>, <danieldboca@yahoo.com>, <cprasqui@yahoo.de>, <jamesmubs@yahoo.co.uk>, <driland@hotmail.com>, <harman.brar@live.ca>
From: "ko" <joko@xxxxx.com.mx>
Mime-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
fyl seqel
fadyni kuwydu wyfev http://www.echipamentelaborator.ro/movie.htm saqa v gaci b
nyhekun papaq
+++++++++++++++++++++++++++++++++++++++++++
I know our server is configured so that relaying is closed and authorization is required to send mail. But they are using a sneaky trick to place the mail in the queue because as long as I can tell they are not using an account to authorize but they are using a domain that is hosted on our server.
Here is a bit from /var/log/messages:
Aug 17 12:03:12 canada7 xinetd[1429]: START: smtp pid=11924 from=::ffff:187.162.75.104
Aug 17 12:03:19 canada7 xinetd[1429]: START: smtp pid=13837 from=::ffff:171.99.143.254
Aug 17 12:03:22 canada7 xinetd[1429]: START: smtp pid=14423 from=::ffff:190.18.37.99
Aug 17 12:03:23 canada7 xinetd[1429]: EXIT: smtp status=0 pid=11924 duration=11(sec)
Aug 17 12:03:24 canada7 xinetd[1429]: START: submission pid=15369 from=::ffff:173.193.188.226
Aug 17 12:03:24 canada7 xinetd[1429]: EXIT: submission status=0 pid=15369 duration=0(sec)
Aug 17 12:03:25 canada7 xinetd[1429]: START: smtp pid=15513 from=::ffff:212.200.204.103
And here a bit from /usr/local/psa/var/log/maillog:
Aug 17 12:04:30 canada7 qmail-queue-handlers[21097]: Handlers Filter before-queue for qmail started ...
Aug 17 12:04:30 canada7 qmail-queue-handlers[21029]: starter: submitter[21080] exited normally
Aug 17 12:04:30 canada7 qmail-queue-handlers[21038]: starter: submitter[21096] exited normally
Aug 17 12:04:30 canada7 qmail-queue-handlers[21041]: starter: submitter[21078] exited normally
Aug 17 12:04:30 canada7 qmail-queue-handlers[21043]: from=meg@xxxxx.com.mx
Aug 17 12:04:30 canada7 qmail-queue-handlers[21043]: to=adaamalafiisah@yahoo.com
Aug 17 12:04:30 canada7 qmail-queue-handlers[21043]: to=paulkey2013@yahoo.com
Aug 17 12:04:30 canada7 qmail-queue-handlers[21043]: to=ambanicrony@yahoo.com
Aug 17 12:04:30 canada7 qmail-queue-handlers[21043]: handlers_stderr: SKIP
Aug 17 12:04:30 canada7 qmail-queue-handlers[21043]: SKIP during call 'check-quota' handler
Aug 17 12:04:30 canada7 spf filter[21103]: Starting spf filter...
Aug 17 12:04:30 canada7 qmail-queue-handlers[21043]: handlers_stderr: SKIP
Aug 17 12:04:30 canada7 qmail-queue-handlers[21043]: SKIP during call 'spf' handler
Aug 17 12:04:30 canada7 spf filter[21104]: Starting spf filter...
Aug 17 12:04:30 canada7 qmail-queue-handlers[21043]: handlers_stderr: SKIP
Aug 17 12:04:30 canada7 qmail-queue-handlers[21043]: SKIP during call 'spf' handler
Aug 17 12:04:30 canada7 spf filter[21105]: Starting spf filter...
Aug 17 12:04:30 canada7 qmail-queue-handlers[21043]: handlers_stderr: SKIP
Aug 17 12:04:30 canada7 qmail-queue-handlers[21043]: SKIP during call 'spf' handler
Aug 17 12:04:30 canada7 qmail-queue-handlers[21043]: starter: submitter[21106] exited normally
Aug 17 12:04:30 canada7 qmail-queue-handlers[21108]: Handlers Filter before-queue for qmail started ...
Aug 17 12:04:30 canada7 qmail-queue-handlers[21109]: Handlers Filter before-queue for qmail started ...
Aug 17 12:04:30 canada7 qmail-queue-handlers[21063]: from=huj@xxxxx.com.mx
Aug 17 12:04:30 canada7 qmail-queue-handlers[21063]: to=way2zoned44@hotmail.com
Aug 17 12:04:30 canada7 qmail-queue-handlers[21063]: to=asdfga@adsf.com
Aug 17 12:04:30 canada7 qmail-queue-handlers[21063]: to=jimmiew50@gmail.com
Aug 17 12:04:30 canada7 qmail-queue-handlers[21063]: to=slejun@yahoo.com
Aug 17 12:04:30 canada7 qmail-queue-handlers[21063]: to=mnoentil@yahoo.com
Aug 17 12:04:30 canada7 qmail-queue-handlers[21063]: handlers_stderr: SKIP
Aug 17 12:04:30 canada7 qmail-queue-handlers[21063]: SKIP during call 'check-quota' handler
Aug 17 12:04:30 canada7 spf filter[21118]: Starting spf filter...
Aug 17 12:04:30 canada7 qmail-queue-handlers[21063]: handlers_stderr: SKIP
Aug 17 12:04:30 canada7 qmail-queue-handlers[21063]: SKIP during call 'spf' handler
They are sending the mail from a lot of different machines.
I don't know how to stop it and I was wondering if you do.
Here are three samples.
Thanks for your help.
+++++++++++++++++++++++++++++++++++++++++++
Received: (qmail 14598 invoked from network); 17 Aug 2013 11:25:12 -0500
Received: from undef-pesochin-kh.maxnet.ua (HELO pjqwsp) (178.165.84.164)
by canada7.xxxxxxxxxx.com with ESMTPA; 17 Aug 2013 11:25:12 -0500
From: "Xwe Apife" <rugic@xxxxx.com.mx>
To: <tn_sika@yahoo.com>, <mjgman23@googlemail.com>, <smores1998@yahoo.com>, <spacecowboy210@yahoo.com>
Subject:
Date: Sat, 17 Aug 2013 17:16:18 -0700
Mime-Version: 1.0
Content-Type: text/plain; charset=utf-7
zy w
xaruwoq qonoxes kigytoz vup dyd http://www.sogz.ru/movies.htm
poqoz vydu wipoxa
+++++++++++++++++++++++++++++++++++++++++++
Received: (qmail 14983 invoked from network); 17 Aug 2013 11:25:18 -0500
Received: from mm-55-57-120-178.dynamic.pppoe.mgts.by (HELO kabemrylxeb) (178.120.57.55)
by canada7.xxxxxxxxxx.com with ESMTPA; 17 Aug 2013 11:25:17 -0500
Date: Sat, 17 Aug 2013 17:16:23 -0700
From: "Fvuso Jw" <fe@xxxxx.com.mx>
To: <max.rawley@yahoo.com>, <duraens@gmail.com>, <pyronancyrey@aol.com>, <aria_aryan70@yahoo.com>, <crk2430@hotmail.com>, <mg109@gateway.net>, <madison22star@hotmail.com>, <mduong999@aol.com>, <kripal.masughat@gmail.com>, <redneckmatty@comcast.net>
Subject:
Mime-Version: 1.0
Content-Type: text/plain; charset="iso-8859-7"
p me http://www.francoiscavallier.com/video.htm?narybatot r
xes g
+++++++++++++++++++++++++++++++++++++++++++
Received: (qmail 16013 invoked from network); 17 Aug 2013 11:25:32 -0500
Received: from unknown (HELO eunnbyspirt) (109.229.174.161)
by canada7.xxxxxxxxxx.com with ESMTPA; 17 Aug 2013 11:25:31 -0500
Subject:
Date: Sat, 17 Aug 2013 17:16:37 -0700
To: <0billyboy7x@yahoo.com>, <grneyes420@hotmail.com>, <1957210eb@gmail.com>, <burgosjose@ymail.com>, <danieldboca@yahoo.com>, <cprasqui@yahoo.de>, <jamesmubs@yahoo.co.uk>, <driland@hotmail.com>, <harman.brar@live.ca>
From: "ko" <joko@xxxxx.com.mx>
Mime-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
fyl seqel
fadyni kuwydu wyfev http://www.echipamentelaborator.ro/movie.htm saqa v gaci b
nyhekun papaq
+++++++++++++++++++++++++++++++++++++++++++