Huge Problem with SPAM!

vovaNux

Verified User
Joined
Nov 27, 2006
Messages
82
Hello!

I among with several my friends faced the problem with SPAM. I am quite a newbie in exim; here is what I have, could you, please, assist me to find the problem.

I am getting about 1000 messages telling me that message delivery has failed. Here are the headers of the message attached:

Return-Path: <[email protected]>
Received: from 20179163139.user.veloxzone.com.br (20179163139.user.veloxzone.com.br [201.79.163.139] (may be forged))
by ns1.first-zone.com (8.12.10/8.12.10) with ESMTP id kARJX4Pf073118
for <[email protected]>; Mon, 27 Nov 2006 13:33:05 -0600 (CST)
(envelope-from [email protected])
Received: from [143.166.175.183] (port=4413 helo=jbQEtfs)
by qkWjohdZEyqgcg with asmtp
id bMLArG-ytbNBk-41
for [email protected]; Mon, 27 Nov 2006 17:33:17 -0200
From: "copy distribute" <[email protected]>
To: [email protected]
Subject: debut album Ten
Date: Mon, 27 Nov 2006 17:33:00 -0200
Message-ID: <000e01c7125a$d90d90d0$8ba34fc9@casa>
MIME-Version: 1.0
Content-Type: text/plain;
charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.6626
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2962

I've changed my real domain name to mydomain.com. And here is another one:

Received: from host-196.218.119.185.tedata.net ([196.218.185.119]) by hw_nt.hyopwoon.co.kr with Microsoft
SMTPSVC(5.0.2195.6713);
Tue, 28 Nov 2006 00:48:52 +0900
Received: from [179.198.14.128] (port=4054 helo=ugOISpJQh)
by skNXtIyTSUq with asmtp
id sPtapH-fdeHfC-43
for [email protected]; Sun, 12 Nov 2006 17:01:18 +0200
Message-ID: <000801c7066b$602df380$00000000@sicowin>
From: "available" <[email protected]>
To: [email protected]
Subject: collected via pen diaries
Date: Sun, 12 Nov 2006 17:01:04 +0200
MIME-Version: 1.0
Content-Type: text/plain;
format=flowed;
charset="windows-1256";
reply-type=original
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2900.2180
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
Return-Path: [email protected]
X-OriginalArrivalTime: 27 Nov 2006 15:48:53.0625 (UTC) FILETIME=[8A507E90:01C7123B]

I've got Catch-All-E-mail option set for this account. I cannot understand what's really happening as I cannot find my e-mail addresses as the message originators in my exim log. I also tried to use tcpdump with no success however.

Sender addresses are different and all of them look like <word>@mydomain.com. These addresses do not really exist and the mail send to them is caught to an e-mail account.

Please, assist, how can I fix it and whether the situation depends on my server. How do I verify that?

Need urgent help. Thank you in advance!
 
I have no idea what you're asking us to solve for you.

Just sending us headers of emails you got tells us nothing.

Do you run your own DA server? If so, then you need to give us information about specific emails NOT getting to the server.

You should never use a catchall account. It attracts spam.

Jeff
 
Yes, I own this dedicated server. The problem as I cannot determine whether these spam e-mails are sent from my server.

I've tried to send e-mails via telnet and standard exim configuration allows me to do this without authentification. You can try it by yourself by introducing the following commands:

mail from: [email protected]
rcpt to: [email protected]
data (ending with "."). Such mail is delevered and I would like to ask you how to prevent such mailings. Now I turned exim off...
 
Hi there,

I am not sure whether this answers your question but I had a similar event this weekend:

two domains received huge amounts of failure mails (spam). In both cases the emails were not sent from my server (I set a maximum number of outgoing emails per user in
Code:
/etc/virtual/limit
).

The basic problem is that someone used their domains as standard reply-to adress in the spam they sent. Not much you can do about that.

The secondary problem was that they had their "catch-all" turned on, so all the failure messages were delivered to their mailbox -> heavy load on the server and diskspace filling up fast.

After I asked the users to switch off their catch-all (they had to think hard which email addresses they had been using...) the serverload dropped to its normal level and most messages were dropped.

I think this sounds like what you need to do. If this is not your problem, then it must be just 'general' spam... So far two-thirds of all mail delivered on my server is flagged as spam and dealt with.

Hope this helps, good luck!

Harro

p.s. now reading your second mail again, it looks like you are an open relay for email? That is something you should definitely block. Search the forum and/or the help pages for this.
 
Everything seems to be just as you described. I cannot identify messages sent from my server as no information is stored in logs.

Does anybody have a working ACL for mail filtering? harro, could you, please, try the commands I posted before at your server and, if everything goes OK, upload an ACL section of your exim.conf?

I would greatly appreciate this as I have been googling for about a day without any good samples...
 
vovaNux said:
I've tried to send e-mails via telnet and standard exim configuration allows me to do this without authentification. You can try it by yourself by introducing the following commands:

mail from: [email protected]
rcpt to: [email protected]
data (ending with ".").
I can't try it because you didn't give your server hostname or IP#.
Such mail is delevered and I would like to ask you how to prevent such mailings.
The standard DA exim.conf file doesn't allow this.

However if you've whitelisted expample.com, then any user can relay through the server. Don't whitelist any domains hosted on the server.
Now I turned exim off...
I can't test anything if exim is turned off.

Jeff
 
vovaNux said:
Does anybody have a working ACL for mail filtering?
SpamBlocker ACL-based blocking is included in the standard DA configuration file.

In order for it to work for a domain you should copy the domain name(s) for which you want it to work, from /etc/virtual/domains to /etc/virtual/use_rbl_domains.

You don't have to restart anything.

Jeff
 
Back
Top