Re: Website link for 194.143.132.10
"Alexey Lobanov (dsbl)" <[email protected]>
| Newsgroups | gmane.mail.spam.dsbl.admin |
|---|---|
| Organization | DSBL volunteer |
| Message-ID | <[email protected]> |
Hello. On 18/02/06 18:06, Philippe JEAN - Prosygma Hébergement wrote: > Dear Alexey, > > We upgraded our system ( Merak 8.3.8 ) > As I can see I think everithing is now secure ... Please note that the point of failure was not Merak software bug but your password database. Now you have disabled SMTP authentification, so the mentioned security hole is closed. It may appear again if you allow SMTP AUTH option in Merak. > > Please, can you confirm me and remove our IP ? You and only you can do it. Please find the message from DSBL to <[email protected]> dated 2006/Feb/14 15:18:20 UTC and visit the magic URL in this message. This procedure will prove us that you are able to read alerts and reports related to your host activity, and it will be enough for delisting. Alexey > > Thanks a lot > > > Hello. > > On 17/02/06 12:42, Philippe JEAN - Prosygma Hébergement wrote: > >> Dear Alexey Lobanov, >> >> Thanks a lot for your help >> I performed tests on >> > http://www.antispam-ufrj.pads.ufrj.br/cgi-bin/test-relay.cgi?host_to_test=19 >> 4.143.132.10 >> and it said : >> >> Relay test result >> All tests performed, no relays accepted by remote host. >> >> Can you simply say me on wich test dslbl failed ? > > All the necessary information is available in links from "Messages from > this host" section at http://dsbl.org/listing?194.143.132.10 > > An example: > > IP: 194.143.132.10 > Input IP: 194.143.132.10 > Transport: smtp > Message Received: 2006/02/16 13:39:14 UTC > Message Sent By: anonymous > Extended Information for Transport: > AUTH LOGIN, user=test > MAIL FROM:<[email protected]> > RCPT TO:<[email protected]> > > We see that your system has easily guessable password for user "test". > And, possibly, for many other accounts, because you obviously do not run > any password strength auditing tool in your system. > > Professional spammers intensively use this class of vulnerabilities > since mid-2002, they just check about 200 combinations of typical > accounts and simple passwords. Same DSBL test does. > > Alexey > > >> >> >> Cordialement, >> >> ******************************************************** >> Prosygma se developpe en dehors des frontieres : >> consultez : http://www.sygmahosting.ma >> ******************************************************** >> >> ----------------------------------------- >> Philippe JEAN >> Société Akilao Prosygma Hébergement >> Batiment PROLOGUE I >> La Pyrénéenne >> 31312 LABEGE Cedex >> http://www.prosygma.com >> Service technique : 08 92 23 01 15 >> Service commercial : 05 61 75 96 30 >> Fax : 05 61 75 96 30 >> ----------------------------------------- >> >> De : Alexey Lobanov (dsbl) <[email protected]> >> À : Philippe JEAN - Prosygma Hébergement <[email protected]> >> CC : [email protected] >> Répondre à : [email protected] >> Date : 16 févr. 2006 - 14:46 >> >> >> >> Hello again. >> >> On 16/02/06 16:06, Alexey Lobanov (dsbl) wrote: >> >>> May we hope that you have performed a full internal security audit and >>> your system has no more weak passwords? >> No, we may not :-( Your system is still vulnerable and is still abused. >> >> http://dsbl.org/message?32240035 >> >> >