| I hate to spoil your day, but it is possible.  I had such an experience 
| about a year ago.  We were using an old version of the popular form mail 
| script formail.pl.  The version in question had a security issue that 
| allowed a spammer to turn my webserver into a mail relay.  Because the 
| mail was going through formmail.pl, it came out just looking like any 
| other mail sent from my mail server.  We were subsequently listed on 
| spamcop, etc, etc.  Was a real mess that took days to sort out.
| 

I believe this is different, because the mail was actually coming from *your
server*, and not just using your domain name, as was posted earlier.

We also are experiencing an enormous amount of bounced messages
indicating a bunch of ficticious addresses at one of our domains.
it also appears they are spamming a ton of msn.com addresses
as all the bounces we are getting indicate that.

I was able to catch a bunch of these and view the source networks
then turned on forwarding to the abuse@ at those networks for
a short while. I'm sure that won't do much, but who knows.

Greg

----- Original Message ----- 
From: "Greg Zartman" <[EMAIL PROTECTED]>
To: "Jim Ford" <[EMAIL PROTECTED]>
Cc: <[EMAIL PROTECTED]>
Sent: Friday, July 04, 2003 11:45 AM
Subject: Re: [SAtalk] <OT> HELP: Someone is using my domain name to send spam


| 
| >>Not unless the spammer also forges headers to make the email
| >>look like it's coming from the IP that corresponds with the
| >>email address. RBL blacklisting is done based on the IP info in
| >>the headers, not on domain names in the email.
| > 
| > 
| > Thanks for the reassurance! If it becomes a problem I'll filter out emails
| > addressed from mysel, as I very rarely email myself except for testing
| > purposes.
| 
| 
| I hate to spoil your day, but it is possible.  I had such an experience 
| about a year ago.  We were using an old version of the popular form mail 
| script formail.pl.  The version in question had a security issue that 
| allowed a spammer to turn my webserver into a mail relay.  Because the 
| mail was going through formmail.pl, it came out just looking like any 
| other mail sent from my mail server.  We were subsequently listed on 
| spamcop, etc, etc.  Was a real mess that took days to sort out.
| 
| The good news was that that we responded to one of the spam messages (a 
| advertisement for morgage refinacing) and the offending company acutally 
| called us back!!!  I turned the *&@#$!s into the local authorities.
| 
| Regards,
| 
| -- 
| Greg J. Zartman, P.E.
| Vice-President
| 
| Logging Engineering International, Inc.
| 1243 West 7th Avenue
| Eugene, Oregon 97402
| 541-683-8383   541-683-8144
| www.leiinc.com
| 
| 
| 
| -------------------------------------------------------
| This SF.Net email sponsored by: Free pre-built ASP.NET sites including
| Data Reports, E-commerce, Portals, and Forums are available now.
| Download today and enter to win an XBOX or Visual Studio .NET.
| http://aspnet.click-url.com/go/psa00100006ave/direct;at.asp_061203_01/01
| _______________________________________________
| Spamassassin-talk mailing list
| [EMAIL PROTECTED]
| https://lists.sourceforge.net/lists/listinfo/spamassassin-talk


-------------------------------------------------------
This SF.Net email sponsored by: Free pre-built ASP.NET sites including
Data Reports, E-commerce, Portals, and Forums are available now.
Download today and enter to win an XBOX or Visual Studio .NET.
http://aspnet.click-url.com/go/psa00100006ave/direct;at.asp_061203_01/01
_______________________________________________
Spamassassin-talk mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/spamassassin-talk

Reply via email to