Re: 216.37.20.20

Alexey Lobanov <[email protected]> Fri, 29 Dec 2006 04:10:24 +0300
Newsgroups gmane.mail.spam.dsbl.admin
Message-ID <[email protected]>
Hello.

29.12.2006 3:55, Leah Peters пишет:

> IF we find an Info and/or Admin account in our SAM (which as of yet,
> we have not)

This idea about local SAM was a guess only. I don't know and I may not
know how does your internal authentification system works.

> and delete or change the passwords, can you remove us
> from the list?

No, because DSBL cannot check it. The ONLY delisting criteria is
"accountability": you have to prove that you are able to receive and
read your "postmaster" (or "abuse") mail. In theory, you may even not to
fix passwords, but in this case your server will be nearly instantly
listed back.

Alexey

> 
> Leah J. Peters
> 
> 
> -----Original Message----- From: Alexey Lobanov
> [mailto:[email protected]] Sent: Thursday, December 28, 2006 7:43 PM 
> To: Leah Peters Cc: [email protected] Subject: Re: [DSBL-Contact]
> 216.37.20.20
> 
> Hello.
> 
> 29.12.2006 3:28, Leah Peters пишет:
> 
>> Since the vulnerabilities are happening on accounts that I do NOT
>> run on my network,
> 
> How it looks from the sender side:
> 
> Connecting to 216.37.20.20... done. <<< 220 **********************
>>>> EHLO lobanov.sp.ru
> <<< 250-mailfilter2003.TIG.local <<< 250-AUTH GSSAPI NTLM LOGIN <<<
> 250 XA
>>>> AUTH LOGIN
> <<< 334 VXNlcm5hbWU6
>>>> aW5mbw==
> <<< 334 UGFzc3dvcmQ6
>>>> aW5mbw==
> <<< 235 2.7.0 Authentication successful.
>>>> MAIL FROM:<[email protected]>
> <<< 250 2.1.0 [email protected] OK
>>>> RCPT TO:<[email protected]>
> <<< 250 2.1.5 [email protected]
>>>> DATA
> <<< 354 Start mail input; end with <CRLF>.<CRLF>
>>>> (message)
> <<< 250 2.6.0  <[email protected]>
> Queued mail for delivery
>>>> QUIT
> <<< 221 2.0.0 tobiasemail.TIG.local Service closing transmission
> channel
> 
> ------------------------------------------------------- Server
> accepted message AUTH=login USER=info PASS=<censored> IP=216.37.20.20
>  -------------------------------------------------------
> 
> So, your server definitely knows "info". A standard reason is local 
> accounts: you have no this "info" in the domain, but you have it in
> the local SAM at mailfilter2003.TIG.local. Please check.
> 
>> you are clearly making business decisions for my company.
> 
> No, we are telling you new important details about your corporate 
> computer system features and it's public activity in Internet.
> 
> Alexey
> 
>> Leah J. Peters
>> 
>> 
>> -----Original Message----- From: Alexey Lobanov
>> [mailto:[email protected]] Sent: Thursday, December 28, 2006 7:32
>> PM To: Leah Peters Cc: [email protected] Subject: Re: [DSBL-Contact]
>> 216.37.20.20
>> 
>> Hello Leah.
>> 
>> 29.12.2006 3:17, Leah Peters пишет:
>> 
>>> Alexey,
>>> 
>>> 
>>> 
>>> One question, do YOU have the capability of removing my IP from
>>> the list?
>> I have neither capability nor wish. Your server is a proved and
>> active open relay, and DSBL users (your recipients) may and should
>> know this impleasant fact until you fix the vulnerability and prove
>> that your Postmaster mail is really able to receive alerts and
>> reports.
>> 
>> Alexey
>> 
>> 
>>> 
>>> 
>>> 
>>> 
>>> 
>>> 
>>> 
>