#1 (permalink)  
Old 04-02-2004, 02:20 PM
Registered User
 
Join Date: Dec 2002
Posts: 5
CCorderoR
Exim might be a Open Relay

Hi:

I've been running some tests thought abuse.net system, and i've discovered exim might support relaying...

RSET
<<< 250 Reset OK
>>> MAIL FROM:<spamtest@domain.com>
<<< 250 OK
>>> RCPT TO:<user-xxxxxxxx%nf.abuse.net@domain.com>
<<< 250 Accepted
>>> DATA
<<< 354 Enter message, ending with "." on a line by itself
>>> (message body)
<<< 250 OK id=1B9U79-0003wb-4U

I've received the e-mail:

This is a test of third-party mail relay, generated via the
Network Abuse Clearinghouse at http://www.abuse.net.

Target host = domain.com [xx.xx.xx.xx]
Test performed by <xxx@domain.com> from xx.58.x.48

A well-configured mail server should NOT relay third-party email.
Otherwise, the server is subject to abuse by vandals and spammers,
and probable blacklisting by recipients of the unwanted third-party
e-mail.

For information on how to secure a mail server against third-party
relay, visit <URL: http://www.mail-abuse.org/tsi/>.

I would like to know if this error is already known and if somebody knows how to block relay thought this method.

Regards,
Carlos
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 04-02-2004, 07:01 PM
Registered User
 
Join Date: Aug 2002
Location: Huntington Beach, Ca
Posts: 232
xsenses
I tested with the anonymous test and my server passed all 12 tests it tried.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 04-03-2004, 03:22 AM
Registered User
 
Join Date: Dec 2002
Posts: 5
CCorderoR
Hi:

I've been checking again and i discovered that spam might only be sent to the local users, so... nothing important

Regards,
Carlos
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 04-04-2004, 09:30 PM
Registered User
 
Join Date: May 2003
Location: Netherlands
Posts: 54
keyDet79
Well, I didn't try this yet on my server but this might be a serious bug since I think someone already abused this on one of our servers.

Luckily the Mail Statistics in WHM display 'Top 50 sending hosts by message count' - if there is any abnormal behaviour you can just block the IPs of the domains used to send this spam. Since I did this I noticed I no longer have huge peaks in the 'received' AND 'delivered' stats list. I had about 2 large peaks a day, along with very high load during their spamming. I definately caught this bastard.
__________________

ICQ: 51034232
MSN: simex@wxs.nl
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 03:36 PM.


Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
© cPanel Inc