RE: Website link for 66.172.9.19

Bert Driehuis <[email protected]> Thu, 11 May 2006 04:44:39 +0200 (CEST)
Newsgroups gmane.mail.spam.dsbl.admin
Message-ID <[email protected]>
[ Note: I still do not represent DSBL. I just track [email protected] to 
keep abreast of possible issues that might affect my use of DSBL, and 
occasionally I help out with questions. You may get responses from other 
subscribers to [email protected], possibly even with dissenting opinions. ]

On Wed, 10 May 2006, Jim Guiltinan wrote:

> OK well that provides an explanation thanks Bert.  The messages shown in the
> status report from your web site regarding my server 66.172.9.19 however,
> all say they are Open Relay Test Messages.
>
> Cracked email account passwords are a different issue than Open Relays are
> they not?

Not if they don't hinder the spammer.

> I do have a tarpitting program installed on my mailservers.  So there
> shouldn't be much spam.

Correct -- this kind of relay is used for "high value" spam, which is 
not sent out in huge volumes. In the past, such relays were popular for 
perpetrating personal abuse rather than harping herbal viagra. The 
biggest benefit to the spammer is that the buck for all intents and 
purposes stops at your server: the spam cannot be distingished from a 
legitimate e-mail from one of your users and thus usually flies beneath 
the radar. An additional benefit is that any ISP with a slightly clued 
abuse desk but not familiar with the particular attack will look at a 
spam complaint and say "you probably subscribed to this mailing list, go 
work it out with out customer" (been there, done that, got the T-shirt).

>  However, I don't allow *any* spam sent through my
> servers, customers or not, so I'll check with my Linux consultant to see if
> he can determine which *email* accounts have been cracked.

The DSBL web site lists the user name (login name) that was abusable. 
Check all entries for your IP address, even my cursory look spotted two 
different ones. Better yet, audit all accounts.

> I do have the
> Plesk feature enabled where passwords are checked in the dictionary and
> rejected if they are found in the dictionary, however, perhaps this is more
> effective on my Plesk 7 server than my Plesk 6.5 (of which the .19 IP
> represents.)  I do know that I've been under attack with crackers attempting
> to gain access to the system, as I can tell from my logs.

I can't tell either which password was used, however, if this was our 
pet spammer the password was trivial (he tries something like a dozen 
per account).

Please note that DSBL is not in the business of attributing blame. If 
the spam stops and in the process you prove that you're reachable for 
complaints, DSBL has achieved two small milestones towards its goal.