Re: Website link for 168.187.78.193

"Alexey Lobanov (dsbl)" <[email protected]> Tue, 30 Oct 2007 17:54:39 +0300
Newsgroups gmane.mail.spam.dsbl.admin
Organization DSBL volunteer
Message-ID <[email protected]>
Hello.

30.10.2007 15:35, Bobin Michael пишет:

> Dear Alexey,
> 
> I checked the security measured we applied to our mail server and we never find anything suspicious.

Too bad. It means that your security check had not find an open door:
trivial passwords for some trivial account names. Please read once more
the link to Spamhaus referred in my first reply. After that please run
any internal auditing tool checking all passwords against a basic
dictionary and trivial derivatives. If this audit will find something
and you fix all the found, it will be absolutely enough. If it will find
nothing, it will mean that you use a wrong auditing scheme.

> 
> In your previous mail you stated that " Just because you do not fix the vulnerability in your system. It still 
> works." Could you please tell me what vulnerability you experiencing from my mail server?

http://dsbl.org/relay-methods#SMTPAUTHrelaying
http://www.spamhaus.org/rokso/evidence.lasso?rokso_id=ROK2669

> 
> I can see DSBL is only blocking my mail server IP.

DSBL just tries to follow the real spammer's industry practice.

> 
> I can't keep continue listing of my mail server IP on your block list. Now it's affecting our day to day mailing activity.

Your mail activity may be a secondary problem comparing to your server
"owned" by criminals through the insecure authentication system.

Alexey

> 
> Regards,
> Bobin
> 
> -----Original Message-----
> From: Alexey Lobanov [mailto:[email protected]] 
> Sent: 28/10/2007 2:09 PM
> To: Bobin Michael
> Cc: [email protected]
> Subject: Re: [DSBL-Contact] Website link for 168.187.78.193
> 
> Hello.
> 
> 28.10.2007 12:35, Bobin Michael пишет:
> 
>> Dear DSBL,
>>
>>  
>>
>> This related with the listing of my mail server IP in your list.
>>
>>  
>>
>> I wonder why am listing again and again?
> 
> Just because you do not fix the vulnerability in your system. It still 
> works.
> 
>>  
>>
>> I already removed my mail server from your list 2 times. Now again it's
>> showing mine listed on your list.
>>
>>  
>>
>> Can please tell me why it's happening again and again? what should I do
>> to avoid such listing in the future?
> 
> Please:
> 
> 1. Read once more "Extended transport information" in the relayed tests.
> All them are available in "Messages from this host" section at
> http://dsbl.org/listing?168.187.78.193; the last test messahe was 
> relayed few minutes ago from RU to NY.US.
> 
> 2. Read some background at
> http://dsbl.org/relay-methods#SMTPAUTHrelaying and
> http://www.spamhaus.org/rokso/evidence.lasso?rokso_id=ROK2669
> During last weeks this technique is being used for a massive "phishing"
> campaign, and your server seems to be one of many participants.
> 
> 3. Make FULL internal security audit. We have absolutely no reasons to
> hope that "test" is your only vulnerable account and that this
> severe security hole had been used for SMTP access only.
> 
> 4. Repeat the delisting request after Oct 31 05:35:21 UTC.
> 
> Alexey
> DSBL volunteer
> 
>>  
>>
>> Regards,
>>
>> Bobin
>>
>>  
>>
>>  
>>
>>  
>>
>>  
>>
>>
>>
>> *************************DISCLAIMER******************************************
>> The information contained in this e-mail message and any attached files 
>> are confidential information and intended solely for the use of the 
>> individual or entity to whom they are addressed.This transmission may 
>> contain information that is privileged,confidential or exempt from 
>> disclosure under applicable law. If you have received this e-mail in error, 
>> please notify the sender immediately and delete all copies. If you are not 
>> the intended recipient, any disclosure,copying, distribution, or use of the
>> information contained herein is STRICTLY PROHIBITED.
>> Path accepts no responsibility for any errors ,omissions computer viruses 
>> and other defects.
>> *****************************************************************************
>>
> 
> 
> *************************DISCLAIMER******************************************
> The information contained in this e-mail message and any attached files 
> are confidential information and intended solely for the use of the 
> individual or entity to whom they are addressed.This transmission may 
> contain information that is privileged,confidential or exempt from 
> disclosure under applicable law. If you have received this e-mail in error, 
> please notify the sender immediately and delete all copies. If you are not 
> the intended recipient, any disclosure,copying, distribution, or use of the
> information contained herein is STRICTLY PROHIBITED.
> Path accepts no responsibility for any errors ,omissions computer viruses 
> and other defects.
> *****************************************************************************