Re: 216.37.20.20

Alexey Lobanov <[email protected]> Fri, 29 Dec 2006 03:43:27 +0300
Newsgroups gmane.mail.spam.dsbl.admin
Message-ID <[email protected]>
Hello.

29.12.2006 3:28, Leah Peters пишет:

> Since the vulnerabilities are happening on accounts that I do NOT run on my network,

How it looks from the sender side:

Connecting to 216.37.20.20... done.
<<< 220 **********************
>>> EHLO lobanov.sp.ru
<<< 250-mailfilter2003.TIG.local
<<< 250-AUTH GSSAPI NTLM LOGIN
<<< 250 XA
>>> AUTH LOGIN
<<< 334 VXNlcm5hbWU6
>>> aW5mbw==
<<< 334 UGFzc3dvcmQ6
>>> aW5mbw==
<<< 235 2.7.0 Authentication successful.
>>> MAIL FROM:<[email protected]>
<<< 250 2.1.0 [email protected] OK
>>> RCPT TO:<[email protected]>
<<< 250 2.1.5 [email protected]
>>> DATA
<<< 354 Start mail input; end with <CRLF>.<CRLF>
>>> (message)
<<< 250 2.6.0  <[email protected]> Queued
mail for delivery
>>> QUIT
<<< 221 2.0.0 tobiasemail.TIG.local Service closing transmission channel

-------------------------------------------------------
Server accepted message
AUTH=login USER=info PASS=<censored> IP=216.37.20.20
-------------------------------------------------------

So, your server definitely knows "info". A standard reason is local
accounts: you have no this "info" in the domain, but you have it in the
local SAM at mailfilter2003.TIG.local. Please check.

> you are clearly making business decisions for my company.

No, we are telling you new important details about your corporate
computer system features and it's public activity in Internet.

Alexey

> 
> Leah J. Peters
>  
> 
> -----Original Message-----
> From: Alexey Lobanov [mailto:[email protected]] 
> Sent: Thursday, December 28, 2006 7:32 PM
> To: Leah Peters
> Cc: [email protected]
> Subject: Re: [DSBL-Contact] 216.37.20.20
> 
> Hello Leah.
> 
> 29.12.2006 3:17, Leah Peters пишет:
> 
>> Alexey,
>>
>>  
>>
>> One question, do YOU have the capability of removing my IP from the
>> list?
> 
> I have neither capability nor wish. Your server is a proved and active
> open relay, and DSBL users (your recipients) may and should know this
> impleasant fact until you fix the vulnerability and prove that your
> Postmaster mail is really able to receive alerts and reports.
> 
> Alexey
> 
> 
>>  
>>
>>  
>>
>>  
>>
>>
>