#1 (permalink)  
Old 06-28-2006, 05:53 AM
Registered User
 
Join Date: Jun 2005
Posts: 13
flen is on a distinguished road
CBL Problems

Hi,

One of our servers is in the CBL Blacklist. I've requested serval removals but it still comes back in the blacklist. The people of CBL can't give me a solution or tell me where the problem exactly is.

- Server hostname is setted up right
- Reverse DNS is okay
- Nothing strange in mail queue as far as I could see
- No other blacklists, only CBL
- Running PhpSuExec, no mail is send under nobody (right?)
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 06-29-2006, 01:04 AM
Registered User
 
Join Date: Oct 2003
Posts: 1,742
dalem is on a distinguished road
check that a cgi script is not conecting directly to the mail server via localhost there is a couple of BB scripts that do this and it connects as somthing@localhost and thats why its getting into to the CBL
__________________
Lowest Host/Empire Technology LLC
Affordable hosting solutions http://lowesthost.com
VPS solutions http://empire-hosting.net/vpsspecial.html
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 06-29-2006, 01:31 AM
AndyReed's Avatar
Registered User
 
Join Date: May 2004
Location: Minneapolis, MN
Posts: 2,208
AndyReed is on a distinguished road
Quote:
Originally Posted by flen
The people of CBL can't give me a solution or tell me where the problem exactly is.

- Server hostname is setted up right
- Reverse DNS is okay
- Nothing strange in mail queue as far as I could see
- No other blacklists, only CBL
- Running PhpSuExec, no mail is send under nobody (right?)
In addition to what dalem suggested, you need to make sure that there are no spammers in-house. It is very likely that a spammer, through one of your clients, downloaded and installed a script on your server. So, you need to find out where that script, or scripts, is/are located and remove them. Overall, secure your server. Good luck!
__________________
Andy Reed
Dedicated server hosting, Colocation Services Server Management, and cPanel Licenses
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 07-01-2006, 07:00 AM
Registered User
 
Join Date: Jun 2005
Posts: 13
flen is on a distinguished road
Like I said, there is nothing strange to see. I can't find any spam scripts and running serval things like Mod_Security, Open_Basedir, PHPSuExec, etc .
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 07-05-2006, 04:14 AM
Registered User
 
Join Date: Jun 2005
Posts: 13
flen is on a distinguished road
No suggestions further? . Server is still daily on CBL and nothing strange to see :/.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old 07-05-2006, 11:51 AM
chirpy's Avatar
Moderator
 
Join Date: Jun 2002
Location: Go on, have a guess
Posts: 13,495
chirpy will become famous soon enough
Only the maintainers of the list can tell you why or how you got on the list, so you're going to have to pursue it with them.
__________________
Jonathan Michaelson
cPanel Forum Moderator

Need your cPanel servers secured and tuned?
cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
http://www.configserver.com
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #7 (permalink)  
Old 07-07-2006, 05:25 AM
Registered User
 
Join Date: Jun 2005
Posts: 13
flen is on a distinguished road
The problem is that they only can tell me "there is something wrong with your mailserver configuration". And there it is a standard cPanel configuration :/.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #8 (permalink)  
Old 07-07-2006, 06:30 PM
Registered User
 
Join Date: Aug 2005
Posts: 122
oulzac is on a distinguished road
wich cbl is it?
most of them have a contact were you can email them directly for further assistance.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #9 (permalink)  
Old 09-07-2006, 04:27 PM
Registered User
 
Join Date: May 2003
Location: Seattle
Posts: 94
payne
This has been happening to me to for the past several days. http://cbl.abuseat.org
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #10 (permalink)  
Old 09-19-2006, 01:05 AM
Registered User
 
Join Date: May 2003
Location: Seattle
Posts: 94
payne
Mine was due to a script that was sending a HELO command over a smtp connection. Instead of HELO myservername.com, it was doing HELO emailrecipient.com. Apparently when done to the wrong server this gets you on the blacklist somehow. I fixed the script and haven't been relisted.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #11 (permalink)  
Old 09-19-2006, 01:16 AM
Registered User
 
Join Date: Feb 2003
Posts: 48
Jorge
I tried to contact them asking for some help (otherwise is almost impossible to know which may be the reason) and I keep receiving the same "auto-responder" message.

BTW, I sent you a PM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #12 (permalink)  
Old 09-19-2006, 03:37 AM
Registered User
 
Join Date: May 2003
Location: Seattle
Posts: 94
payne
I had the autoresponder problem with a different blacklist, spamcop, and ended up disabling the autoresponder feature in whm. I also disabled spam trapper for the same reason. I haven't had problems with spamcop since then (a few days running).
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #13 (permalink)  
Old 09-20-2006, 01:54 PM
Registered User
 
Join Date: May 2003
Location: Seattle
Posts: 94
payne
ok... just got blacklisted again. I just followed the advice at http://www.farhad.ca/2006/07/27/how-...sages-in-exim/ and sent an email to deputies[at]admin.spamcop.net asking if they can give more info on what exactly is being bounced to a spamcop trap.

I'm wondering if it might be this in my exim.conf:

accept domains = +local_domains
local_parts = postmaster:abuse
deny message = Message rejected because $sender_fullhost \
is blacklisted at $dnslist_domain see $dnslist_text
!hosts = +relay_hosts
!authenticated = *
dnslists = dnsbl.njabl.org : \
sbl.spamhaus.org : \
list.dsbl.org : \
cbl.abuseat.org : \
relays.ordb.org
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #14 (permalink)  
Old 09-20-2006, 02:25 PM
Registered User
 
Join Date: Feb 2003
Posts: 48
Jorge
Is incredible, CBL can't tell me what's the HELO that they get, thefore, it makes me impossible to find out in the whole server where it may be the problem.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #15 (permalink)  
Old 09-20-2006, 02:53 PM
Registered User
 
Join Date: Aug 2002
Posts: 1,068
sparek-3 is on a distinguished road
I have run into similar issues before. Can't say as if I really have any suggestions.

As others have said, you will really just have to communicate with the list administrators to determine why you are listed and what can be done to get off of the list. Of course, this is what you are trying to do and you're not getting any responses. I too have this problem from time to time.

If a spam blacklist is going to block one of our servers, I would appreciate it if they could give me information pertaining to the blacklisting whenever it is requested.

As much as I depise AOL, I do like their feedback loop system. With their feedback loop system, we can see exactly who is responsible for getting our servers blacklisted at AOL. This same type of information would be useful with other spam blacklists.

When one of our servers gets blacklisted, I will write the list administrators and explain to them that the issue is likely a user forwarding mail, an autoresponder, or perhaps some script on the server that is responsible for the blacklisting. I'm not going to disagree with them that they should not have blacklisted the server. But, if they can give me the information that resulting in the server being blacklisted, then I can attempt to trace that down to a specific user and educate or inform that user of their action. However, this usually goes on deaf ears.

If blacklist maintainers really want to help stop spam, I think they should develop some way of providing this information. Use AOL's feedback system as a basis.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 07:41 AM.


Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
© cPanel Inc