/* Please excuse the cross-posting to debian-user and smartlist. I think both are likely to have useful input on this and it feels fairly urgent to me! */
I run a few not particularly large Email lists using smartlist under Hamm. I have subscription confirmation on and have been very happy with the setup. I've had problems as the medical school site which hosts my box has been abused by spammers (45k messages in 24hrs) and had big hassle with the blacklists etc. as a result. Now a spam has gone out on one of my lists last night. The name from which it comes is not on the list nor have I had copies of any attempts by this person to join (which I receive as default normally). The header shows s/he has definitely used the list: Status: U Return-Path: <[EMAIL PROTECTED]> Received: from psyctcsghms.ac.uk (psyctc [194.80.201.68]) by ribosome.sghms.ac.uk (8.8.8+Sun/8.8.8) with ESMTP id GAA15491; Fri, 20 Nov 1998 06:11:39 GMT Received: (from [EMAIL PROTECTED]) by psyctcsghms.ac.uk (8.8.8/8.8.8/Debian/GNU) id GAA21614; Fri, 20 Nov 1998 06:07:50 GMT Resent-Date: Fri, 20 Nov 1998 06:07:50 GMT From: [EMAIL PROTECTED] Message-Id: <[EMAIL PROTECTED]> Date: Fri, 20 Nov 98 03:00 ADT To: [EMAIL PROTECTED] Subject: Over 20 Joined In The Last 5 Days - Join Now & Get In near The Top! Resent-Message-ID: <"VxzYWD.A.nRF.2cQV2"@psyctc> Resent-From: [EMAIL PROTECTED] Resent-Reply-To: [EMAIL PROTECTED] X-Mailing-List: <[EMAIL PROTECTED]> archive/latest/9 X-Loop: [EMAIL PROTECTED] Precedence: list Resent-Sender: [EMAIL PROTECTED] X-list: [EMAIL PROTECTED] X-Unsub: To leave, send text 'unsubscribe' to sign-speak- [EMAIL PROTECTED] X-List-Unsubscribe: <mailto:sign-speak- [EMAIL PROTECTED]@body=unsubscribe> X-List-Administrator: [EMAIL PROTECTED] (Chris Evans) X-PMFLAGS: 33554560 0 1 P50480.CNM The stuff at the top shows something odd with the missing stop in psyctcsghms.ac.uk but the psyctc and the IP address are correct. The X-List: and other stuff at the bottom is very definitely the stuff I've put into the list that it should add to all outgoing post so s/he's definitely hacked into the list somehow. I found one other with the same body to the message but a very different header: Received: from nexus.chilenet.cl ([EMAIL PROTECTED] [200.2.98.4]) by psyctcsghms.ac.uk (8.8.8/8.8.8/Debian/GNU) with SMTP id GAA21596 for <[EMAIL PROTECTED]>; Fri, 20 Nov 1998 06:01:49 GMT From: [EMAIL PROTECTED] Received: by nexus.chilenet.cl (/\oo/\ Smail3.1.29.1 #29.17) id <[EMAIL PROTECTED]>; Thu, 19 Nov 98 04:28 ADT Message-Id: <[EMAIL PROTECTED]> Date: Fri, 20 Nov 98 02:56 ADT To: [EMAIL PROTECTED] Subject: Over 20 Joined In The Last 5 Days - Join Now & Get In near The Top! X-PMFLAGS: 33554560 0 1 P3D710.CNM I'm a bit out of my depth here but willing to do anything reasonable to minimise the risks of this happening again. Does anyone recognise the probable exploit that was used or have advice about how to do more to track down the route used and to block off this or other likely exploits? TIA, Chris