MESSAGE
DATE | 2008-12-16 |
FROM | Ron Guerin
|
SUBJECT | Re: [NYLXS - HANGOUT] tracking mail
|
Ruben Safir wrote: > On Mon, Dec 15, 2008 at 08:50:30PM -0500, Ruben Safir wrote: >> Dec 15 17:43:10 www2 sendmail[12062]: mBFMh644012061: to="|exec >> /usr/bin/procmail", ctladdr= (1000/104), >> delay=00:00:01, xdelay=00:00:00, mailer=prog, pri=64695, dsn=2.0.0, >> stat=Sent >> Dec 15 17:43:10 www2 sendmail[12065]: mBFMhArZ012065: >> Authentication-Warning: www2.mrbrklyn.com: majordomo set sender to >> lest-hangout-at-nylxs.com using -f >> Dec 15 17:43:10 www2 sendmail[12065]: mBFMhArZ012065: >> from=lest-hangout-at-nylxs.com, size=4753, class=-60, nrcpts=1, >> msgid=<20081216691.3195.qmail-at-COM33>, relay=majordomo-at-localhost >> Dec 15 17:43:12 www2 sendmail[12066]: mBFMhADf012066: >> from=, size=5010, class=-60, nrcpts=1, >> msgid=<20081216691.3195.qmail-at-COM33>, proto=ESMTP, daemon=MTA, >> relay=localhost [127.0.0.1] >> Dec 15 17:43:12 www2 sendmail[12065]: mBFMhArZ012065: >> to=hangout-outgoings, ctladdr=lest-hangout-at-nylxs.com (150/2), >> delay=00:00:02, xdelay=00:00:02, mailer=relay, pri=142753, >> relay=[127.0.0.1] [127.0.0.1], dsn=2.0.0, stat=Sent (mBFMhADf012066 >> Message accepted for delivery) >> >> Does this have meaning to someone. It almost looks like someone managed >> to relay something through procmail directly though my mail account. >> >> Ruben >> > > > truthfuly, I don't know how this happened. I'm not going to be home > for another week. At that timme I will upgrade the mail server > and the mailing list engine, not to mention procmail. And we'll > go from there
I'm a little confused. What are these headers from and what do you think happened here exactly? If this is in regards to the Gucci thing, the only thing you should be concerning yourself with is your anti-spam measures employed on this mailing list. Spam *will* get sent from a *valid subscriber address* (forged) to the *list address* from time to time, and Majordomo is going to happily deliver it unless you take steps to examine the things your *valid subscribers* throw at it.
From the Gucci mail:
X-Originating-IP: [159.107.151.114] X-Originating-Email: [ruben-at-mrbrklyn.com]
So, if we can trust these headers (and we cannot, but we're going to anyway), this message was from "you", from an IP address under the administrative authority of RIPE in the Netherlands. While it is known that you, Ruben I. Safir are out of town, upstate New York is not Europe, therefore I'm going to conclude without further analysis that someone forged your address onto some spam and using whatever nifty spam engine they have, matched it with another mrbrklyn.com address they know about (hangout-at-mrbrklyn.com) and viola, we're all getting mail from Hangout extolling the virtues of fake Gucci crap.
What happened here is unworthy of you spending any time on it except to consider installing SpamAssassin, and if you already have this list front-ended by SA, you need to tweak it.
- Ron
|
|