Re: Website link for 207.173.187.220

Alexey Lobanov <[email protected]> Tue, 05 Dec 2006 22:03:47 +0300
Newsgroups gmane.mail.spam.dsbl.admin
Message-ID <[email protected]>
Leisher, Doug пишет:

> I guess I'll just have to wait the 7 days then start this process all
> over again and try to keep better track. 

..and wait more one week if everything will be repeated. I don't like 
it. Please wait a bit, I'll generate several manual tests and you will 
try to locate them in your logs.

First probe. Do you see my uncuccessful attempts to relay a test through 
your system NOW? The test was started half an hour ago and still works, 
the source IP is same as in my e-mails.

  I have checked all my logs,
> message tracking, and my special email account (where all spam-marked
> email goes to) and cannot find any reference to any message sent by
> @dsbl.org.

Note that the message had empty reverse-path, just because it was 
created by a dumb robot being unable to process any delivery reports. 
See see RFC-821 Page 15. However, it is not really important, because (I 
repeat) you know the queue ID and exact time of the SMTP transaction.

Alexey

> 
> Doug. . .
> 
> -----Original Message----- From: Alexey Lobanov
> [mailto:[email protected]] Sent: Tuesday, December 05, 2006 1:45 PM 
> To: Leisher, Doug Cc: [email protected] Subject: Re: [DSBL-Contact]
> Website link for 207.173.187.220
> 
> Hello.
> 
> Leisher, Doug пишет:
> 
>> I don't know the answer to your question regarding messages per 
>> second but we are a very small school district and probably only 
>> average about 5,000 emails per hour (including spam).  According or
>>  Task Manager, our server is under utilized as it rarely gets above
>>  50% CPU utilization.
> 
> I suspected it, and my question was rhetoric. You definitely should
> be able to find 2006/Nov/29 16:23:21 UTC (note timezone!) in your
> logs and look through all nearby events.
> 
>> I've been watching my server for the last several days.  There have
>>  not been any Exchange queues created to send to dsbl.org, unless
>> it creates then deletes so fast that I can't see it.
> 
> I believe, the magic word is "logging". Those damned computers do
> many things too quickly for a human eye, but every important events
> must be logged. It is not a law requirement, it is a "Good Internet
> Practice" :-). A condition for survival.
> 
>> I was also able to send mail to my postmaster account from one of
>> my external accounts, receive that message, then reply to it with
>> no problems.
> 
> I trust you that your system delivers SOME mail to Postmaster. But we
>  see also that some other mail is accepted and lost. Does it mean
> that your system operates in non-deterministic way?
> 
>> The info I got from DSBL.ORG's website regarding the removal
>> process indicated that they would send an email to my postmaster
>> account.  In the email would be a link that I need to click.
>> Assuming this is true,
> 
> Yes. I has been working as an ISP security officer, and I used DSBL 
> delisting procedure nearly daily for my clients. It works as
> described.
> 
>> I would have had to have received the email in order to either 
>> click the link or at least reply to the email, but I didn't.
> 
> So, now you know about a major bug in your system. Please read also 
> http://dsbl.org/faq-listed#randomlythrowsaway
> 
> Alexey
> 
> 
>> Thanks! Doug
>> 
>> 
>> -----Original Message----- From: Alexey Lobanov 
>> [mailto:[email protected]] Sent: Tuesday, December 05, 2006 12:48
>> PM To: Leisher, Doug Cc: [email protected] Subject: Re: [DSBL-Contact]
>>  Website link for 207.173.187.220
>> 
>> Hello Doug.
>> 
>> Leisher, Doug пишет:
>> 
>>> Bert,
>>> 
>>> I did a search on my email server for all messages going to my 
>>> postmaster (either as a recipient or sender) account.  There were
>>>  none from dsbl.org.
>> At http://dsbl.org/listing?207.173.187.220 we can see the queue ID
>>  assigned by your server: <[email protected]>. This
>>  piece of information is intended for message tracking, and it must
>> be sufficient for tracking in server logs. In addition, you know
>> the exact time. How many messages per second does your system
>> accept?
>> 
>>> Other than waiting the week to do this removal process again,
>> I have to note that "next week" attempt will fail in same way if
>> you do not locate and fix the bug.
>> 
>>> is there anyway I can expedite this?
>> No, but there are effective workarounds: 
>> http://dsbl.org/faq-listed#7days
>> 
>> Alexey DSBL volunteer
>> 
>>> Doug
>>> 
>>> -----Original Message----- From: Bert Driehuis 
>>> [mailto:[email protected]] Sent: Friday, December 01, 2006 
>>> 2:28 PM To: Leisher, Doug Cc: [email protected] Subject: RE: 
>>> [DSBL-Contact] Website link for 207.173.187.220
>>> 
>>> [ Note: I do not represent DSBL. I just track [email protected] to 
>>> keep abreast of possible issues that might affect my use of DSBL,
>>>  and occasionally I help out with questions. You may get
>>> responses from other subscribers to [email protected], possibly even
>>> with dissenting opinions. ]
>>> 
>>> On Fri, 1 Dec 2006, Leisher, Doug wrote:
>>> 
>>>> Thanks for your input Bert.  I used the ORDB.org site to test
>>>> for open relays as I've heard that's pretty good.
>>> ORDB is a very good service. Unfortunately, the way it operates 
>>> means that it is extremely conservative, which results in at
>>> least half the open relays and almost all open proxies flying
>>> under ORDB's radar. That's not a criticism of ORDB; their
>>> conservatism makes them acceptable
>>> 
>>> to a different audience than DSBL's typical large-site
>>> postmasters.
>>> 
>>> 
>>>> I was able to send an email to my postmaster account via an 
>>>> outside email address.  I then saw that in my postmaster inbox 
>>>> and was able to open it and reply to it.  So, if DSBL did send
>>>> a message to my postmaster account, I don't know why it appears
>>>> to be held up.  I also looked at my exchange queues and there
>>>> aren't any for dsbl.org.  If my postmaster account would have
>>>> received such a message and then replied to it, there would be
>>>> an exchange queue for its delivery.
>>> I can't look into your system, and neither can I see more of
>>> DSBL's than
>>> 
>>> you can, but in my experience, when the listing page says it was
>>>  delivered, it was delivered. Most commonly, when message
>>> disappear, they
>>> 
>>> get deleted by a misguided spam filter. Many authors of anti-spam
>>>  tools wilfully disregard an important invariant underlying
>>> e-mail delivery: one should either reject, or accept and deliver,
>>> a message (that delivery can be to a quaranteen folder, that's
>>> okay; deleting it isn't).
>>> 
>>> Your logs really should allow you to find out what happened.
>