MESSAGE
DATE | 2008-12-17 |
FROM | Ruben Safir
|
SUBJECT | Re: [NYLXS - HANGOUT] tracking mail
|
On Tue, Dec 16, 2008 at 10:50:06PM -0500, Ron Guerin wrote: > Ruben Safir wrote: > > On Mon, Dec 15, 2008 at 08:50:30PM -0500, Ruben Safir wrote: > >> Dec 15 17:43:10 www2 sendmail[12062]: mBFMh644012061: to="|exec > >> /usr/bin/procmail", ctladdr= (1000/104), > >> delay=00:00:01, xdelay=00:00:00, mailer=prog, pri=64695, dsn=2.0.0, > >> stat=Sent > >> Dec 15 17:43:10 www2 sendmail[12065]: mBFMhArZ012065: > >> Authentication-Warning: www2.mrbrklyn.com: majordomo set sender to > >> lest-hangout-at-nylxs.com using -f > >> Dec 15 17:43:10 www2 sendmail[12065]: mBFMhArZ012065: > >> from=lest-hangout-at-nylxs.com, size=4753, class=-60, nrcpts=1, > >> msgid=<20081216691.3195.qmail-at-COM33>, relay=majordomo-at-localhost > >> Dec 15 17:43:12 www2 sendmail[12066]: mBFMhADf012066: > >> from=, size=5010, class=-60, nrcpts=1, > >> msgid=<20081216691.3195.qmail-at-COM33>, proto=ESMTP, daemon=MTA, > >> relay=localhost [127.0.0.1] > >> Dec 15 17:43:12 www2 sendmail[12065]: mBFMhArZ012065: > >> to=hangout-outgoings, ctladdr=lest-hangout-at-nylxs.com (150/2), > >> delay=00:00:02, xdelay=00:00:02, mailer=relay, pri=142753, > >> relay=[127.0.0.1] [127.0.0.1], dsn=2.0.0, stat=Sent (mBFMhADf012066 > >> Message accepted for delivery) > >> > >> Does this have meaning to someone. It almost looks like someone managed > >> to relay something through procmail directly though my mail account. > >> > >> Ruben > >> > > > > > > truthfuly, I don't know how this happened. I'm not going to be home > > for another week. At that timme I will upgrade the mail server > > and the mailing list engine, not to mention procmail. And we'll > > go from there > > I'm a little confused. What are these headers from and what do you > think happened here exactly? If this is in regards to the Gucci thing, > the only thing you should be concerning yourself with is your anti-spam > measures employed on this mailing list. Spam *will* get sent from a > *valid subscriber address* (forged) to the *list address* from time to > time, and Majordomo is going to happily deliver it unless you take steps > to examine the things your *valid subscribers* throw at it. > > >From the Gucci mail: > > X-Originating-IP: [159.107.151.114] > X-Originating-Email: [ruben-at-mrbrklyn.com] > > So, if we can trust these headers (and we cannot, but we're going to > anyway), this message was from "you", from an IP address under the > administrative authority of RIPE in the Netherlands. While it is known > that you, Ruben I. Safir are out of town, upstate New York is not > Europe, therefore I'm going to conclude without further analysis that > someone forged your address onto some spam and using whatever nifty spam > engine they have, matched it with another mrbrklyn.com address they know > about (hangout-at-mrbrklyn.com) and viola, we're all getting mail from > Hangout extolling the virtues of fake Gucci crap. > > What happened here is unworthy of you spending any time on it except to > consider installing SpamAssassin, and if you already have this list > front-ended by SA, you need to tweak it. > > - Ron
How is settin up SA going to hel. You'd have to end the recieving side of the server and I'd had thought that SA works on the back end when the message is being delivered.
I just ask everyone to have some patients. I'll know this down like I always do as soon as I get home. I get mail spoofing my adress all the time. These guys found a crack.
Ther should be a way to prevent sendmail from accepting false accounts from wrong IP addresses. My machines allow email relay from the local network. Maybe that is being somehow exploited if Ron is right.
Ruben
-- http://www.mrbrklyn.com - Interesting Stuff http://www.nylxs.com - Leadership Development in Free Software
So many immigrant groups have swept through our town that Brooklyn, like Atlantis, reaches mythological proportions in the mind of the world - RI Safir 1998
http://fairuse.nylxs.com DRM is THEFT - We are the STAKEHOLDERS - RI Safir 2002
"Yeah - I write Free Software...so SUE ME"
"The tremendous problem we face is that we are becoming sharecroppers to our own cultural heritage -- we need the ability to participate in our own society."
"> I'm an engineer. I choose the best tool for the job, politics be damned.< You must be a stupid engineer then, because politcs and technology have been attached at the hip since the 1st dynasty in Ancient Egypt. I guess you missed that one."
© Copyright for the Digital Millennium
|
|