Qmail-Scanner Envelope Details Begin

General Discussion of atomic repo and development projects.

Ask for help here with anything else not covered by other forums.
netweblogic
Forum User
Forum User
Posts: 29
Joined: Mon Jan 12, 2009 2:31 pm

Qmail-Scanner Envelope Details Begin

Unread post by netweblogic »

Hello,

I've got the archiving running and archiving every email. I then move the emails to an account that I can pop into. I keep getting tons of messages that are from an unknown sender and subject. the contents are below:

*** Qmail-Scanner Envelope Details Begin ***
X-Qmail-Scanner-Mail-From: "" via domainname.com
X-Qmail-Scanner-Rcpt-To: ""
X-Qmail-Scanner: 2.02st (clamdscan: 0.94.2/8899. spamassassin: 3.2.5. perlscan: 2.02st. Clear:RC:0(79.108.26.226):. Processed in 0.029352 secs)
*** Qmail-Scanner Envelope Details End ***

Does anyone know where these are coming from and how/if they can be stopped?
scott
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
Posts: 8355
Joined: Wed Dec 31, 1969 8:00 pm
Location: earth
Contact:

Re: Qmail-Scanner Envelope Details Begin

Unread post by scott »

they're coming from 79.108.26.226, so that would imply via either poplocking or a compromised smtp_auth account
netweblogic
Forum User
Forum User
Posts: 29
Joined: Mon Jan 12, 2009 2:31 pm

Re: Qmail-Scanner Envelope Details Begin

Unread post by netweblogic »

Thanks, I didn't think of that bit. However, the IP changes constantly, so it's not an email from my system...

What's happening there exactly?

I've added a regex of ".+" since the mails don't seem to have a from and to header, but I'm still getting some (albeit less than before). However, I'm not sure whether I sloved it or not because I'm still downloading 7000 emails so I'll wait for that to finish and report back...
scott
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
Posts: 8355
Joined: Wed Dec 31, 1969 8:00 pm
Location: earth
Contact:

Re: Qmail-Scanner Envelope Details Begin

Unread post by scott »

could be a botnet too, thats a pretty standard practice to sell spamming or whatever services through one.
Post Reply