Jason on Mon, 30 Sep 2002 14:41:07 -0400


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

Re: [PLUG] spoofing


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Monday 30 September 2002 08H:11, Arthur S. Alexion wrote:
<snip>
>
> I got another bounce from a server in the Ukraine.  This one had a list
> of bad addresses, alphabetically similar usernames, on Russian domains.
>  My MUA doesn't display the Cyrillic fonts (although it will display
> Greek and Asian occasionally), but the bodies of the bounced emails
> look the same.
>
> This leads me to believe that this is not a klez virus thing, but
> rather, a Russian spammer who is using my address.  I'm just concerned
> about whether I should be concerned (if that makes sense).

That makes complete sense.

I didn't pore over your logfiles in great detail, so I apologize if the 
answers to the following questions are covered there. This is definitely a 
growing problem in general.

If you are running your own server, you may want to be concerned. If you are 
having email forwarded to abuse@<yourdomain> or postmaster@<yourdomain> or 
something like that, and you are the postmaster, you may need to look into 
it. If any of these fit your situation, keep the posts coming. I've been 
trying to look into some of these types of problems as well. I host and 
forward email for myself as well as about 5 family members, a social group, 
and one small business at the moment.

Forged spam is a definite problem, and sometimes your email address may be 
used as the forged sender when sent to others. This is a really big problem 
if your email server is being used as an "open relay".

If someone else is handling your email server you may want to inquire with 
them as to what is going on. In this case, it hopefully your email address is 
only being forged as the sender when you are also the recipient.

So, basically, are you the postmaster for alexion.com? Do you actually 
configure your email server and have it open to the world to beat on it, or 
does your ISP have an email server running on your behalf? Do you use 
fetchmail to pull the email from your ISP's email server? If you use 
fetchmail, then if there is a problem, it is most likely your ISP's concern, 
assuming you have adequate firewall protection around your local email 
server.

Good luck and hope this helps,
Jason Nocks
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.7 (GNU/Linux)

iD8DBQE9mJqq3CryLfCgqRkRAuBnAJ9WUiwQ6hdccjWgM1J4AjJtLDicwQCfTFQC
8gw4wMQs4vXYAjUA1AMXLyA=
=J9Gh
-----END PGP SIGNATURE-----

_________________________________________________________________________
Philadelphia Linux Users Group        --       http://www.phillylinux.org
Announcements - http://lists.netisland.net/mailman/listinfo/plug-announce
General Discussion  --   http://lists.netisland.net/mailman/listinfo/plug