/* Please excuse the cross-posting to debian-user and smartlist.  I 
think both are likely to have useful input on this and it feels fairly 
urgent to me! */

I run a few not particularly large Email lists using smartlist under 
Hamm.  I have subscription confirmation on and have been very 
happy with the setup.  I've had problems as the medical school site 
which hosts my box has been abused by spammers (45k 
messages in 24hrs) and had big hassle with the blacklists etc. as 
a result.

Now a spam has gone out on one of my lists last night.  The name 
from which it comes is not on the list nor have I had copies of any 
attempts by this person to join (which I receive as default 
normally).  The header shows s/he has definitely used the list:

Status: U
Return-Path: <[EMAIL PROTECTED]>
Received: from psyctcsghms.ac.uk (psyctc [194.80.201.68])
        by ribosome.sghms.ac.uk (8.8.8+Sun/8.8.8) with ESMTP 
id GAA15491;
        Fri, 20 Nov 1998 06:11:39 GMT
Received: (from [EMAIL PROTECTED])
        by psyctcsghms.ac.uk (8.8.8/8.8.8/Debian/GNU) id 
GAA21614;
        Fri, 20 Nov 1998 06:07:50 GMT
Resent-Date: Fri, 20 Nov 1998 06:07:50 GMT
From: [EMAIL PROTECTED]
Message-Id: <[EMAIL PROTECTED]>
Date: Fri, 20 Nov 98 03:00 ADT
To: [EMAIL PROTECTED]
Subject: Over 20 Joined In The Last 5 Days - Join Now & Get In 
near The Top!
Resent-Message-ID: <"VxzYWD.A.nRF.2cQV2"@psyctc>
Resent-From: [EMAIL PROTECTED]
Resent-Reply-To: [EMAIL PROTECTED]
X-Mailing-List: <[EMAIL PROTECTED]> archive/latest/9
X-Loop: [EMAIL PROTECTED]
Precedence: list
Resent-Sender: [EMAIL PROTECTED]
X-list: [EMAIL PROTECTED]
X-Unsub: To leave, send text 'unsubscribe' to sign-speak-
[EMAIL PROTECTED]
X-List-Unsubscribe: <mailto:sign-speak-
[EMAIL PROTECTED]@body=unsubscribe>
X-List-Administrator: [EMAIL PROTECTED] (Chris Evans)
X-PMFLAGS: 33554560 0 1 P50480.CNM

The stuff at the top shows something odd with the missing stop in 
psyctcsghms.ac.uk but the psyctc and the IP address are correct. 
The X-List: and other stuff at the bottom is very definitely the stuff 
I've put into the list that it should add to all outgoing post so s/he's 
definitely hacked into the list somehow.

I found one other with the same body to the message but a very 
different header:

Received: from nexus.chilenet.cl ([EMAIL PROTECTED] 
[200.2.98.4])
        by psyctcsghms.ac.uk (8.8.8/8.8.8/Debian/GNU) with 
SMTP id GAA21596
        for <[EMAIL PROTECTED]>; Fri, 20 Nov 1998 
06:01:49 GMT
From: [EMAIL PROTECTED]
Received: by nexus.chilenet.cl (/\oo/\ Smail3.1.29.1 #29.17)
        id <[EMAIL PROTECTED]>; Thu, 19 Nov 
98 04:28 ADT
Message-Id: <[EMAIL PROTECTED]>
Date: Fri, 20 Nov 98 02:56 ADT
To: [EMAIL PROTECTED]
Subject: Over 20 Joined In The Last 5 Days - Join Now & Get In 
near The Top!
X-PMFLAGS: 33554560 0 1 P3D710.CNM

I'm a bit out of my depth here but willing to do anything reasonable 
to minimise the risks of this happening again.  Does anyone 
recognise the probable exploit that was used or have advice about 
how to do more to track down the route used and to block off this 
or other likely exploits?  

TIA,


Chris

Reply via email to