Spam but not from my server

Forum for getting help with Project Gamera, Spamassassin, Clamav, qmail-scanner and other anti-spam tools.
CrK01
Forum User
Forum User
Posts: 94
Joined: Wed Jun 06, 2007 10:49 am

Spam but not from my server

Unread post by CrK01 »

Hi all,


I'm a centos 5 user, with ASL product, using gamera, etc working OK more or less, PAX kernel ( asl kernel ) etc

my problem is that i get so many deliverie failures, seems that some worm is sending mails out of our servers, but the "from" are on our domain. ( newlightsystems.XXX )

Example:
The original message was received at Tue, 7 Oct 2008 19:32:39 GMT
from host212-117-dynamic.59-82-r.retail.telecomitalia.it [82.59.117.212]

----- The following addresses had permanent fatal errors -----
<info.de@adinstruments.com>
(reason: 550 Blocked by policy: No SPAM please! (#V))

----- Transcript of session follows -----
... while talking to mailin.rzone.de.:
>>> >>> DATA
<<< 550 Blocked by policy: No SPAM please! (#V)
554 5.0.0 Service unavailable
... while talking to newmail-g1.xinnetdns.com.:
>>> >>> DATA
<<< 451 SPF failed
<info.cn@adinstruments.com>... Deferred: 451 SPF failed



Reporting-MTA: dns; adinstrnew.vwh.net
Received-From-MTA: DNS; host212-117-dynamic.59-82-r.retail.telecomitalia.it
Arrival-Date: Tue, 7 Oct 2008 19:32:39 GMT

Final-Recipient: RFC822; f.oberheinrich@adinstruments.de
Action: failed
Status: 5.2.0
Remote-MTA: DNS; mailin.rzone.de
Diagnostic-Code: SMTP; 550 Blocked by policy: No SPAM please! (#V)
Last-Attempt-Date: Tue, 7 Oct 2008 19:32:41 GMT



Asunto:
Сайт принесет Вам прибыль
De:
Гедеон Петя <comercial@newlightsystems.XXX>
Fecha:
Tue, 7 Oct 2008 20:32:38 +0100
Para:
<info.au@adinstruments.com>

Здравствуйте!

Предлагаю раскрутить Ваш сайт по следующей схеме:

Размещаем его на специальном хостинге и делаем массовую рассылку писем с указанием Вашего сайта.

Это принесет от нескольких сотен до нескольких тысяч посетителей посетителей на сайт.

Также можем новый создать сайт.

Цены - от 3500 руб.

Звоните сейчас: (Ч95)5896953
ICQ: 39 179 6624
is there any way to stop this ? it seems that are .RU domains, and i've blocked with geoblocking

thanks
breun
Long Time Forum Regular
Long Time Forum Regular
Posts: 2813
Joined: Sat Aug 20, 2005 9:30 am
Location: The Netherlands

Unread post by breun »

This is called backscatter, which can be pretty hard to stop. There is a ruleset for SpamAssassin for backscatter, but you need to provide it with a list of relays that you send your outbound mail through. If your clients are using their ISP's relays to send out mail it can be quite an impossible task to maintain a complete list of outbound relays, so this is not so easy to use in a shared hosting environment AFAIK.

Sadly, Project Gamera servers are also backscatter machines. :(
Lemonbit Internet Dedicated Server Management
CrK01
Forum User
Forum User
Posts: 94
Joined: Wed Jun 06, 2007 10:49 am

Unread post by CrK01 »

yes is a shared environment this will be very hard to track :(

thanks for the info ;)

( is there any way or rule to block bounces returning from certain domains, for example .ru domains ? tis would be a nice solution as the spammers are always from .ru or similar )

thanks
CrK01
Forum User
Forum User
Posts: 94
Joined: Wed Jun 06, 2007 10:49 am

Unread post by CrK01 »

is there a way to configure that I can recieve only deliveries from my mail server, not from the gamera ?

thanks,
Post Reply