RE: 12.177.9.5
"David Cornett" <[email protected]>
| Newsgroups | gmane.mail.spam.dsbl.admin |
|---|---|
| Message-ID | <200509140816587.SM02004@david0105> |
The accounts you have mentioned were unfortunately created for test purposes by us. We have, as of yesterday, gone through our entire user list. If you would, go ahead and run the test for me one more time. We are also going to the extent of sending out a mandatory password change to all of our users. And there will be some password rules applied to them. -----Original Message----- From: Alexey Lobanov [mailto:[email protected]] Sent: Tuesday, September 13, 2005 8:44 AM To: David Cornett Cc: [email protected] Subject: Re: [DSBL-Contact] 12.177.9.5 Hello. On 09/13/2005 05:33 PM, David Cornett wrote: > Is there any testing process that we can request before we try your removal > process. This maillist is a right place for this request. The standard test based on real spammer activity is in progress now. ...Oops. It had an effect: Server accepted message AUTH=cram-md5 USER=backup PASS=backup IP=12.177.9.5 The situation is much more serious than an open relay. In difference from "test", "backup" is an administrative account. It is VERY POSSIBLE that whole system has been compromised and backdoored already through this account. The practical recommendation is simple: disconnect, reinstall from scratch, set new passwords for all accounts, apply security audits. Sorry. > We have gotten rid of our open relay and also the test / test > account. I believe, a proper action could be to use any automated tool for internal password auditing. There is a plenty of security tools being able to detect accounts with weak passwords. Any external test will not be so effective and can miss something important. best, Alexey DSBL volunteer