Re: Website link for 168.187.78.193

"Alexey Lobanov (dsbl)" <[email protected]> Wed, 31 Oct 2007 10:33:44 +0300
Newsgroups gmane.mail.spam.dsbl.admin
Organization DSBL volunteer
Message-ID <[email protected]>
Hello.

31.10.2007 10:04, Bobin Michael пишет:

> Dear Alexy,
> 
> Thanks for your comments.
> 
> As per your mail, I did the password auditing using Microsoft
> Baseline Security Analyzer and found that few of my user account has
> enabled password never expires option and I did the correction of
> that. Now I hope it will resolve the vulnerability issue with my mail
> server.

No, it is still active. It means that your auditing scheme was wrong:
this tool did not check the quality of existing passwords against a
dictionary. It does not matter how often does your user change the
password if the password itself is "password" or something similar.

> 
> Could you please tell me any other vulnerability you again
> experiencing from my mail server?

Unfortunately, I am not an expert in MS-Windows security and don't know
good auditing tools. Possibly, you need assistance from Microsoft.

Alexey


> 
> Regards, Bobin
> 
> 
> -----Original Message----- From: Alexey Lobanov (dsbl)
> [mailto:[email protected]] Sent: 30/10/2007 5:55 PM To: Bobin Michael
>  Cc: DSBL Subject: Re: [DSBL-Contact] Website link for 168.187.78.193
> 
> 
> Hello.
> 
> 30.10.2007 15:35, Bobin Michael пишет:
> 
>> Dear Alexey,
>> 
>> I checked the security measured we applied to our mail server and
>> we never find anything suspicious.
> 
> Too bad. It means that your security check had not find an open door:
>  trivial passwords for some trivial account names. Please read once
> more the link to Spamhaus referred in my first reply. After that
> please run any internal auditing tool checking all passwords against
> a basic dictionary and trivial derivatives. If this audit will find
> something and you fix all the found, it will be absolutely enough. If
> it will find nothing, it will mean that you use a wrong auditing
> scheme.
> 
>> In your previous mail you stated that " Just because you do not fix
>> the vulnerability in your system. It still works." Could you please
>> tell me what vulnerability you experiencing from my mail server?
> 
> http://dsbl.org/relay-methods#SMTPAUTHrelaying 
> http://www.spamhaus.org/rokso/evidence.lasso?rokso_id=ROK2669
> 
>> I can see DSBL is only blocking my mail server IP.
> 
> DSBL just tries to follow the real spammer's industry practice.
> 
>> I can't keep continue listing of my mail server IP on your block
>> list. Now it's affecting our day to day mailing activity.
> 
> Your mail activity may be a secondary problem comparing to your
> server "owned" by criminals through the insecure authentication
> system.
> 
> Alexey
> 
>> Regards, Bobin
>> 
>> -----Original Message----- From: Alexey Lobanov
>> [mailto:[email protected]] Sent: 28/10/2007 2:09 PM To: Bobin
>> Michael Cc: [email protected] Subject: Re: [DSBL-Contact] Website link
>> for 168.187.78.193
>> 
>> Hello.
>> 
>> 28.10.2007 12:35, Bobin Michael пишет:
>> 
>>> Dear DSBL,
>>> 
>>> 
>>> 
>>> This related with the listing of my mail server IP in your list.
>>> 
>>> 
>>> 
>>> I wonder why am listing again and again?
>> Just because you do not fix the vulnerability in your system. It
>> still works.
>> 
>>> 
>>> 
>>> I already removed my mail server from your list 2 times. Now
>>> again it's showing mine listed on your list.
>>> 
>>> 
>>> 
>>> Can please tell me why it's happening again and again? what
>>> should I do to avoid such listing in the future?
>> Please:
>> 
>> 1. Read once more "Extended transport information" in the relayed
>> tests. All them are available in "Messages from this host" section
>> at http://dsbl.org/listing?168.187.78.193; the last test messahe
>> was relayed few minutes ago from RU to NY.US.
>> 
>> 2. Read some background at 
>> http://dsbl.org/relay-methods#SMTPAUTHrelaying and 
>> http://www.spamhaus.org/rokso/evidence.lasso?rokso_id=ROK2669 
>> During last weeks this technique is being used for a massive
>> "phishing" campaign, and your server seems to be one of many
>> participants.
>> 
>> 3. Make FULL internal security audit. We have absolutely no reasons
>> to hope that "test" is your only vulnerable account and that this 
>> severe security hole had been used for SMTP access only.
>> 
>> 4. Repeat the delisting request after Oct 31 05:35:21 UTC.
>> 
>> Alexey DSBL volunteer
>> 
>>> 
>>> 
>>> Regards,
>>> 
>>> Bobin
>>> 
>>> 
>>> 
>>> 
>>> 
>>> 
>>> 
>>> 
>>> 
>>> 
>>> 
>>> *************************DISCLAIMER******************************************
>>>  The information contained in this e-mail message and any
>>> attached files are confidential information and intended solely
>>> for the use of the individual or entity to whom they are
>>> addressed.This transmission may contain information that is
>>> privileged,confidential or exempt from disclosure under
>>> applicable law. If you have received this e-mail in error, please
>>> notify the sender immediately and delete all copies. If you are
>>> not the intended recipient, any disclosure,copying, distribution,
>>> or use of the information contained herein is STRICTLY
>>> PROHIBITED. Path accepts no responsibility for any errors
>>> ,omissions computer viruses and other defects. 
>>> *****************************************************************************
>>> 
>>> 
>> 
>> *************************DISCLAIMER******************************************
>>  The information contained in this e-mail message and any attached
>> files are confidential information and intended solely for the use
>> of the individual or entity to whom they are addressed.This
>> transmission may contain information that is
>> privileged,confidential or exempt from disclosure under applicable
>> law. If you have received this e-mail in error, please notify the
>> sender immediately and delete all copies. If you are not the
>> intended recipient, any disclosure,copying, distribution, or use of
>> the information contained herein is STRICTLY PROHIBITED. Path
>> accepts no responsibility for any errors ,omissions computer
>> viruses and other defects. 
>> *****************************************************************************
>> 
> 
> 
> 
> *************************DISCLAIMER******************************************
>  The information contained in this e-mail message and any attached
> files are confidential information and intended solely for the use of
> the individual or entity to whom they are addressed.This transmission
> may contain information that is privileged,confidential or exempt
> from disclosure under applicable law. If you have received this
> e-mail in error, please notify the sender immediately and delete all
> copies. If you are not the intended recipient, any
> disclosure,copying, distribution, or use of the information contained
> herein is STRICTLY PROHIBITED. Path accepts no responsibility for any
> errors ,omissions computer viruses and other defects. 
> *****************************************************************************