Re: Website link for 204.249.70.10
"Alexey Lobanov (dsbl)" <[email protected]>
| Newsgroups | gmane.mail.spam.dsbl.admin |
|---|---|
| Message-ID | <[email protected]> |
Hello. On 08/09/05 23:23, Jason Isla wrote: > Hi Paul, thanks for the response. That's pretty much the plan. We've > replaced the Exchange server and are reloading that system. Nothing > should respond on that address, but the host and domain will be the > same. Should we still need to go through the delisting process? Yes. You still need to prove that you really control this server and you really are able to receive abuse reports to any standard contact address. > The > e-mail addresses listing for the ip address are for are T1 provider > ([email protected] and [email protected]). They're tough to get > to, and we don't have access to those accounts. That's bad, because Netsync also blocks effectively your ability to have your own public contact. The host name written in reverse DNS by Netsync is simply false: ~$ host 204.249.70.10 10.70.249.204.in-addr.arpa domain name pointer 204-249-70-10.netsync.net. ~$ host 204-249-70-10.netsync.net Host 204-249-70-10.netsync.net not found: 3(NXDOMAIN) Unfortunately, I have no any good advice for you. Anyway, you need help from your ISP: they have either to delist your host via their contact or write something more informative to the reverse DNS zone. I believe, the latter will be the better solution. Note also that an oviously false (= not pointing back to this IP-address) name in reverse DNS can be an independent reason for mail rejection. Best, Alexey DSBL volunteer > > > Thanks, > Jason. > > > -----Original Message----- > From: Paul Howarth [mailto:[email protected]] > Sent: Thursday, September 08, 2005 11:47 AM > To: Jason E. Isla > Cc: [email protected] > Subject: Re: [DSBL-Contact] Website link for 204.249.70.10 > > Hello, > > Jason E. Isla wrote: > >>Before I try to delist our ip address, which is just an internal >>Microsoft Exchange 2000 server, I want to understand how and why we > > got > >>listed in the first place. >>Here's the message I got: >> >>IP: 204.249.70.10 >>Input IP: 204.249.70.10 >>Transport: socks4 <http://dsbl.org/relay-methods#SOCKS4relaying> >>Input Port: 12683 >>Message Received: 2005/08/25 18:17:26 UTC >>Message Sent By: bertd >>Extended Information for Transport: >>Connect to 205.231.29.241:25 >> >> >>Full Message: >> >>Message-ID: <GnD/zX0qraYis//+TsxgbMVI4biVs3W0@anonymous@invalid> >>To: <[email protected]> >>Subject: Open SOCKS4 Proxy test message >> >>I think I took care of the problem by eliminating anonymous access to >>the virtual smtp server in Exchange, but don't know how to check. >>Can you help enlighten me a little? > > > The message didn't go through your Exchange server. There was an open > socks proxy at port 12683. The unusual port number is indicative of the > machine at that IP address being trojanned, probably as a result of a > virus infection. A complete reinstall, including all security patches, > is the best solution. > > Regards, Paul. > >