Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Results 1 to 4 of 4
  1. #1
    Member
    Join Date
    Dec 2002
    Posts
    5

    Default Exim might be a Open Relay

    Hi:

    I've been running some tests thought abuse.net system, and i've discovered exim might support relaying...

    RSET
    <<< 250 Reset OK
    >>> MAIL FROM:<spamtest@domain.com>
    <<< 250 OK
    >>> RCPT TO:<user-xxxxxxxx%nf.abuse.net@domain.com>
    <<< 250 Accepted
    >>> DATA
    <<< 354 Enter message, ending with "." on a line by itself
    >>> (message body)
    <<< 250 OK id=1B9U79-0003wb-4U

    I've received the e-mail:

    This is a test of third-party mail relay, generated via the
    Network Abuse Clearinghouse at http://www.abuse.net.

    Target host = domain.com [xx.xx.xx.xx]
    Test performed by <xxx@domain.com> from xx.58.x.48

    A well-configured mail server should NOT relay third-party email.
    Otherwise, the server is subject to abuse by vandals and spammers,
    and probable blacklisting by recipients of the unwanted third-party
    e-mail.

    For information on how to secure a mail server against third-party
    relay, visit <URL: http://www.mail-abuse.org/tsi/>.

    I would like to know if this error is already known and if somebody knows how to block relay thought this method.

    Regards,
    Carlos

  2. #2
    Member
    Join Date
    Aug 2002
    Location
    Huntington Beach, Ca
    Posts
    232

    Default

    I tested with the anonymous test and my server passed all 12 tests it tried.

  3. #3
    Member
    Join Date
    Dec 2002
    Posts
    5

    Default

    Hi:

    I've been checking again and i discovered that spam might only be sent to the local users, so... nothing important

    Regards,
    Carlos

  4. #4
    Member
    Join Date
    May 2003
    Location
    Netherlands
    Posts
    54

    Default

    Well, I didn't try this yet on my server but this might be a serious bug since I think someone already abused this on one of our servers.

    Luckily the Mail Statistics in WHM display 'Top 50 sending hosts by message count' - if there is any abnormal behaviour you can just block the IPs of the domains used to send this spam. Since I did this I noticed I no longer have huge peaks in the 'received' AND 'delivered' stats list. I had about 2 large peaks a day, along with very high load during their spamming. I definately caught this bastard.

    ICQ: 51034232
    MSN: simex@wxs.nl

Similar Threads & Tags
Similar threads

  1. why is my exim an open relay??
    By corey_s in forum cPanel and WHM Discussions
    Replies: 11
    Last Post: 10-31-2006, 08:08 AM
  2. exim w/open relay
    By kokoman in forum cPanel and WHM Discussions
    Replies: 10
    Last Post: 10-16-2004, 07:37 PM
  3. Exim 280 and below is open relay!
    By sexy_guy in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 08-15-2003, 11:23 PM
  4. Are you open relay with EXIM? Yes you are.
    By pirania1 in forum cPanel and WHM Discussions
    Replies: 58
    Last Post: 06-06-2003, 06:41 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube