Hello It seems my mailserver is listed in CBL.
The message i see is :
This IP is operating (or NATting for a computer that is operating) the "sendsafe" or similar (such as Advanced Mass Sender - AMS) bulk emailing malware. This software is almost exclusively used for sending "Nigerian 419"/"advance fee" frauds or phishing attempts. It is also used occasionally to send pharmaceutical spam.
Sendsafe works by acquiring userid and password (usually stolen) for a valid email account on a mail server. Then, a machine compromised by sendsafe (in this case your IP) makes a SMTP connection to that mail server, authenticates with the compromised email login credentials, and proceeds to send spam emails.
One way to look for this is to look for authenticated outbound SMTP connections from this IP address either on port 25 or port 587. This particular detection was of a SMTP connection made from your IP address to IP address 203.183.65.42.
NOTE When a sendsafe infection starts to send email to the compromised mail server (at 203.183.65.42), it usually sends VERY VERY large quantities all at once. The compromised mail server probably can't relay it as fast as it's receiving it, so will queue it for later delivery. The timestamp we give above is the time which the recipient's mail server received it, _not_ when sendsafe sent it. Therefore, the reception timestamp may be as much as 4 days _after_ the sendsafe infection sent it. So, if you have firewall logs, search for at least the 4 previous days for connections to 203.183.65.42.
DO NOT BOTHER looking for emails in your mail server logs, because these infections DO NOT use your mail server software, and will obviously not show up in your mail server logs.
In some cases it turns out to be a SSH login account (with a weak or compromised password) used to proxy inbound connections to outbound SMTP connections. Check your SSH logs for logins from unusual places (such as Nigeria).
---------------------------------------------------------------------------
But i'm not sure i understand the message.
Are the talking about stolen userid and passwords of emailaccounts on my emailserver?
Is my emailserver sending out spam, or trough another emailserver?
Can someone tell me in simple english what the message above mean and what i need to do to solve this?
The message i see is :
This IP is operating (or NATting for a computer that is operating) the "sendsafe" or similar (such as Advanced Mass Sender - AMS) bulk emailing malware. This software is almost exclusively used for sending "Nigerian 419"/"advance fee" frauds or phishing attempts. It is also used occasionally to send pharmaceutical spam.
Sendsafe works by acquiring userid and password (usually stolen) for a valid email account on a mail server. Then, a machine compromised by sendsafe (in this case your IP) makes a SMTP connection to that mail server, authenticates with the compromised email login credentials, and proceeds to send spam emails.
One way to look for this is to look for authenticated outbound SMTP connections from this IP address either on port 25 or port 587. This particular detection was of a SMTP connection made from your IP address to IP address 203.183.65.42.
NOTE When a sendsafe infection starts to send email to the compromised mail server (at 203.183.65.42), it usually sends VERY VERY large quantities all at once. The compromised mail server probably can't relay it as fast as it's receiving it, so will queue it for later delivery. The timestamp we give above is the time which the recipient's mail server received it, _not_ when sendsafe sent it. Therefore, the reception timestamp may be as much as 4 days _after_ the sendsafe infection sent it. So, if you have firewall logs, search for at least the 4 previous days for connections to 203.183.65.42.
DO NOT BOTHER looking for emails in your mail server logs, because these infections DO NOT use your mail server software, and will obviously not show up in your mail server logs.
In some cases it turns out to be a SSH login account (with a weak or compromised password) used to proxy inbound connections to outbound SMTP connections. Check your SSH logs for logins from unusual places (such as Nigeria).
---------------------------------------------------------------------------
But i'm not sure i understand the message.
Are the talking about stolen userid and passwords of emailaccounts on my emailserver?
Is my emailserver sending out spam, or trough another emailserver?
Can someone tell me in simple english what the message above mean and what i need to do to solve this?