Here is the deal, I just checked our mail queue and noticed that there is a very large amount of emails sitting in there. 2000+! The email is coming from the same email/person/domain going to other accounts. We don't host any of the "from" domains. Server is up-to-date, has latest of everthing and I have Exim SMTP checking to make sure that the user has a GID to send email. So what am I missing here?![]()
Here is an example of those emails:
1AgvJL-00083R-MF-H
mailnull 47 12
<>
1074126275 0
-ident mailnull
-received_protocol local
-body_linecount 31
-frozen 1074126275
-localerror
XX
1
samantha@hostdomino.com
153P Received: from mailnull by server-1.myserver.com with local (Exim 4.24)
id 1AgvJL-00083R-MF
for samantha@hostdomino.com; Wed, 14 Jan 2004 18:24:35 -0600
046 X-Failed-Recipients: amal_1972@rediffmail.com
031 Auto-Submitted: auto-generated
063F From: Mail Delivery System <Mailer-Daemon@server-1.myserver.com>
028T To: samantha@hostdomino.com
059 Subject: Mail delivery failed: returning message to sender
052I Message-Id: <E1AgvJL-00083R-MF@server-1.myserver.com>
038 Date: Wed, 14 Jan 2004 18:24:35 -0600
1AgvJL-00083R-MF-D
This message was created automatically by mail delivery software.
A message that you sent could not be delivered to one or more of its
recipients. This is a permanent error. The following address(es) failed:
amal_1972@rediffmail.com
SMTP error from remote mailer after RCPT TO:<amal_1972@rediffmail.com>:
host mail3.rediffmail.com [203.199.83.132]: 551 Requested action not taken:
mailbox full
------ This is a copy of the message, including all the headers. ------
Return-path: <samantha@hostdomino.com>
Received: from nobody by server-1.myserver.com with local (Exim 4.24)
id 1AgvJK-000837-Jf
for amal_1972@rediffmail.com; Wed, 14 Jan 2004 18:24:34 -0600
To: amal_1972@rediffmail.com
Subject: Unreal Penetrations
From: Samantha <samantha@hostdomino.com>
Reply-To: samantha@hostdomino.com
Errors-To: <samantha@hostdomino.com>
MIME-Version: 1.0
X-Mailer: AOL 6.0 for Windows US sub 10520
Content-type: text/html; charset=iso-8859-1
Message-Id: <E1AgvJK-000837-Jf@server-1.myserver.com>
Date: Wed, 14 Jan 2004 18:24:34 -0600
<html><body bgcolor="#FFFFFF" text="#000000" link="#000000" vlink="#000000" alink="#000000"><table border="0" cellspacing="0" cellpadding="0" align="center"><tr><td align="center"><a href="http://www.cubemagazine.net/up2/PXUGr21thzQsUXkSkjQ.html"><font size="1"><a href="http://www.cubemagazine.net/up2/PXUGr21thzQsUXkSkjQ.html">Tony showed me this site, it's ****************ing awesome!<p>It's got the biggest cocks you've ever seen splitting open the tiniest chicks.The pics are ****************ing unreal.It's also got some of the craziest penetrations.The site is out of control.You're going to love it!</a></font></a><br>
<br>
<a href="http://www.cubemagazine.net/up2/PXUGr21thzQsUXkSkjQ.html" target="_new"><img src="http://www.cubemagazine.net/up2/PXUGr21thzQsUXkSkjQ.png" border="0"></a></td></tr></table><p><center><font size="1"><font color="#ffffff">PXUGr21thzQsUXkSkjQ PXUGr21thzQsUXkSkjQ PXUGr21thzQsUXkSkjQ PXUGr21thzQsUXkSkjQ PXUGr21thzQsUXkSkjQ</font></font></center><p><center><font size="1"><a href="http://www.cubemagazine.net/_PXUGr21thzQsUXkSkjQ.php"><img src="http://www.cubemagazine.net/_PXUGr21thzQsUXkSkjQ/re.jpg" border="0"></a></center></body></html>



LinkBack URL
About LinkBacks
Reply With Quote
Perhaps a shitty thing to do but I got a very fast reply to an email I sent them concerning this 'affiliate' of theirs asking me to stop clogging up their mail server;hehe They also apparently terminated his affiliate account with this particular site and when verifying the page he was advertising to, it appears so. dunno...a bit of justice in that. I'm now simply just failing them immediately with a filter in /etc/antivirus.exim so they never enter the queue which is easy enough and buys time to figure this one out.




