RE: Website link for 63.87.94.131
"Brice Spreitzer" <[email protected]>
| Newsgroups | gmane.mail.spam.dsbl.admin |
|---|---|
| Message-ID | <[email protected]> |
We are no longer send outbound mail through this host. Thank you have a nice day... Regards, Brice Spreitzer Server Administrator CEC/OEG Phone: 847.851.5133 -----Original Message----- From: Alexey Lobanov (dsbl) [mailto:[email protected]] Sent: Wednesday, September 28, 2005 9:36 AM To: Brice Spreitzer Cc: [email protected] Subject: Re: [DSBL-Contact] Website link for 63.87.94.131 Hello. On 28/09/05 17:52, Brice Spreitzer wrote: > I appreciate the further information regarding our listing. After your > last description I was able to find the problem and I have now fixed > this host. I'm afraid, you have fixed only a part of security problems. Instant check: ======================================================== Server accepted AUTH but rejected mail AUTH=login USER=info PASS= IP=63.87.94.131 You may wish to retry this test at a later date if this looks like a temporary condition. ======================================================== > Any help you guys could provide would be greatly > appreciated. The main practical proposal is still same: full internal security audit. All auditing tools instantly detect all accounts with weak or null passwords. After that you have to wait until next week: your yesterday delisting was reset by new relayed message. During this week you may try to use the ISP relay for all outgoing mail, same as dialup users do. It is one of standard workarounds. Alexey > Thanks in advance. > > Regards, > > Brice Spreitzer > Server Administrator > CEC/OEG > Phone: 847.851.5133 > > > -----Original Message----- > From: Alexey Lobanov (dsbl) [mailto:[email protected]] > Sent: Wednesday, September 28, 2005 12:15 AM > To: Brice Spreitzer > Cc: [email protected] > Subject: Re: [DSBL-Contact] Website link for 63.87.94.131 > > Hello. > > On 28/09/05 07:28, Brice Spreitzer wrote: > > >>DSBL, >> >>I have submitted the proper mail to de-list this server. I am a >>little unclear as to how it could have gotten listed. > > > I am sorry, but this sequence of sentences seems to be a bit illogical. > If you are not sure where are the landmines, why do you try to remove > red flags? > > >> I do not see >>the required cookie in the email your server received from our host. >>I have tested this and another of our servers with the same >>configuration (MS Exchange 2003), and all tests indicate this is not >>an open relay. > > > It is still open relay, because of empty password for "/webmaster" > account (and, possibly, other ones). This type of vulnerability is > widely used by professional spammers since mid-2002. > > >>Please provide any further information that you have on this host, or >>any information that can help me to verify this host is secure. > > > Please read again the evidences in "Messages from this host" section at > http://dsbl.org/listing?63.87.94.131. Your host is really insecure, and > the recommended instant action is full internal security audit. It is > more than possible that same unprotected account (or accounts?) was used > for other types of invasion, and this system is backdoored already. > > Best, > Alexey > DSBL volunteer > > > >> I >>have read your entire FAQ and the only thing left (in my mind) is a >>malicous user. Is there any more to the header that your server >>received, maybe something including an end host IP address. If it is >>an internal user or student, I would like to find out who, and why >>this occurred. >> >>Thank you in advance. >> >>Brice Spreitzer Server Administrator Career Education Corp. Online >>Education Group 847.851.5133