Re: Website link for 63.87.94.131

"Alexey Lobanov (dsbl)" <[email protected]>
Newsgroups gmane.mail.spam.dsbl.admin
Organization DSBL volunteer
Message-ID <[email protected]>
Hello.

On 28/09/05 17:52, Brice Spreitzer wrote:

> I appreciate the further information regarding our listing.  After your
> last description I was able to find the problem and I have now fixed
> this host.

I'm afraid, you have fixed only a part of security problems. Instant check:

========================================================
Server accepted AUTH but rejected mail
AUTH=login USER=info PASS= IP=63.87.94.131
You may wish to retry this test at a later date
if this looks like a temporary condition.
========================================================


>  Any help you guys could provide would be greatly
> appreciated.

The main practical proposal is still same: full internal security audit.
All auditing tools instantly detect all accounts with weak or null
passwords.

After that you have to wait until next week: your yesterday delisting
was reset by new relayed message. During this week you may try to use
the ISP relay for all outgoing mail, same as dialup users do. It is one
of standard workarounds.

Alexey

>  Thanks in advance.
> 
> Regards, 
> 
> Brice Spreitzer 
> Server Administrator 
> CEC/OEG 
> Phone: 847.851.5133
> 
> 
> -----Original Message-----
> From: Alexey Lobanov (dsbl) [mailto:[email protected]] 
> Sent: Wednesday, September 28, 2005 12:15 AM
> To: Brice Spreitzer
> Cc: [email protected]
> Subject: Re: [DSBL-Contact] Website link for 63.87.94.131
> 
> Hello.
> 
> On 28/09/05 07:28, Brice Spreitzer wrote:
> 
> 
>>DSBL,
>>
>>I have submitted the proper mail to de-list this server.  I am a
>>little unclear as to how it could have gotten listed.
> 
> 
> I am sorry, but this sequence of sentences seems to be a bit illogical.
> If you are not sure where are the landmines, why do you try to remove
> red flags?
> 
> 
>> I do not see
>>the required cookie in the email your server received from our host.
>>I have tested this and another of our servers with the same
>>configuration (MS Exchange 2003), and all tests indicate this is not
>>an open relay.
> 
> 
> It is still open relay, because of empty password for "/webmaster"
> account (and, possibly, other ones). This type of vulnerability is
> widely used by professional spammers since mid-2002.
> 
> 
>>Please provide any further information that you have on this host, or
>>any information that can help me to verify this host is secure.
> 
> 
> Please read again the evidences in "Messages from this host" section at
> http://dsbl.org/listing?63.87.94.131. Your host is really insecure, and
> the recommended instant action is full internal security audit. It is
> more than possible that same unprotected account (or accounts?) was used
> for other types of invasion, and this system is backdoored already.
> 
> Best,
> Alexey
> DSBL volunteer
> 
> 
> 
>> I
>>have read your entire FAQ and the only thing left (in my mind) is a
>>malicous user.  Is there any more to the header that your server
>>received, maybe something including an end host IP address.  If it is
>>an internal user or student, I would like to find out who, and why
>>this occurred.
>>
>>Thank you in advance.
>>
>>Brice Spreitzer Server Administrator Career Education Corp. Online
>>Education Group 847.851.5133
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.