RE: 216.37.20.20
"Leah Peters" <[email protected]> Thu, 28 Dec 2006 20:08:30 -0500
| Newsgroups | gmane.mail.spam.dsbl.admin |
|---|---|
| Message-ID | <[email protected]> |
Can you tell me what email address you sent the Removal request from? = Our ISP is not able to find the email you sent to [email protected] so = they cannot respond back to it. Leah J. Peters =20 -----Original Message----- From: Alexey Lobanov [mailto:[email protected]]=20 Sent: Thursday, December 28, 2006 8:10 PM To: Leah Peters Cc: [email protected] Subject: Re: [DSBL-Contact] 216.37.20.20 Hello. 29.12.2006 3:55, Leah Peters =D0=C9=DB=C5=D4: > IF we find an Info and/or Admin account in our SAM (which as of yet, > we have not) This idea about local SAM was a guess only. I don't know and I may not know how does your internal authentification system works. > and delete or change the passwords, can you remove us > from the list? No, because DSBL cannot check it. The ONLY delisting criteria is "accountability": you have to prove that you are able to receive and read your "postmaster" (or "abuse") mail. In theory, you may even not to fix passwords, but in this case your server will be nearly instantly listed back. Alexey >=20 > Leah J. Peters >=20 >=20 > -----Original Message----- From: Alexey Lobanov > [mailto:[email protected]] Sent: Thursday, December 28, 2006 7:43 PM=20 > To: Leah Peters Cc: [email protected] Subject: Re: [DSBL-Contact] > 216.37.20.20 >=20 > Hello. >=20 > 29.12.2006 3:28, Leah Peters =D0=C9=DB=C5=D4: >=20 >> Since the vulnerabilities are happening on accounts that I do NOT >> run on my network, >=20 > How it looks from the sender side: >=20 > Connecting to 216.37.20.20... done. <<< 220 ********************** >>>> EHLO lobanov.sp.ru > <<< 250-mailfilter2003.TIG.local <<< 250-AUTH GSSAPI NTLM LOGIN <<< > 250 XA >>>> AUTH LOGIN > <<< 334 VXNlcm5hbWU6 >>>> aW5mbw=3D=3D > <<< 334 UGFzc3dvcmQ6 >>>> aW5mbw=3D=3D > <<< 235 2.7.0 Authentication successful. >>>> MAIL FROM:<[email protected]> > <<< 250 2.1.0 [email protected] OK >>>> RCPT TO:<[email protected]> > <<< 250 2.1.5 [email protected] >>>> DATA > <<< 354 Start mail input; end with <CRLF>.<CRLF> >>>> (message) > <<< 250 2.6.0 <[email protected]> > Queued mail for delivery >>>> QUIT > <<< 221 2.0.0 tobiasemail.TIG.local Service closing transmission > channel >=20 > ------------------------------------------------------- Server > accepted message AUTH=3Dlogin USER=3Dinfo PASS=3D<censored> = IP=3D216.37.20.20 > ------------------------------------------------------- >=20 > So, your server definitely knows "info". A standard reason is local=20 > accounts: you have no this "info" in the domain, but you have it in > the local SAM at mailfilter2003.TIG.local. Please check. >=20 >> you are clearly making business decisions for my company. >=20 > No, we are telling you new important details about your corporate=20 > computer system features and it's public activity in Internet. >=20 > Alexey >=20 >> Leah J. Peters >>=20 >>=20 >> -----Original Message----- From: Alexey Lobanov >> [mailto:[email protected]] Sent: Thursday, December 28, 2006 7:32 >> PM To: Leah Peters Cc: [email protected] Subject: Re: [DSBL-Contact] >> 216.37.20.20 >>=20 >> Hello Leah. >>=20 >> 29.12.2006 3:17, Leah Peters =D0=C9=DB=C5=D4: >>=20 >>> Alexey, >>>=20 >>>=20 >>>=20 >>> One question, do YOU have the capability of removing my IP from >>> the list? >> I have neither capability nor wish. Your server is a proved and >> active open relay, and DSBL users (your recipients) may and should >> know this impleasant fact until you fix the vulnerability and prove >> that your Postmaster mail is really able to receive alerts and >> reports. >>=20 >> Alexey >>=20 >>=20 >>>=20 >>>=20 >>>=20 >>>=20 >>>=20 >>>=20 >>>=20 >=20