1. Advertising
    y u no do it?

    Advertising (learn more)

    Advertise virtually anything here, with CPM banner ads, CPM email ads and CPC contextual links. You can target relevant areas of the site and show ads based on geographical location of the user if you wish.

    Starts at just $1 per CPM or $0.10 per CPC.

is my site Mail being hacked?

Discussion in 'Security' started by toby, Feb 28, 2007.

  1. #1
    Hi guys,

    I have noticed that my site email system has sent out email containing spam.
    The reason i know is because the other guys who receive my mail, emails me back and i saw the sender is . where xxx is any name.

    Is my mail server being hacked? How can i rectify the problem?

    cheers,
     
    toby, Feb 28, 2007 IP
  2. clancey

    clancey Peon

    Messages:
    1,099
    Likes Received:
    63
    Best Answers:
    0
    Trophy Points:
    0
    #2
    Just because the sender of the email purports to be from your domain does not mean that your machine is the source of the email. You would need to see the full header of the email message which was sent to that individual. You need to examine the "Received:" lines in the email header to see if your server's IP address is present. It looks like:

    Received: from mail.MYSERVER.ca ([000.000.000.000] - or -
    Received: from 000.000.000.000

    where the zeroes are your IP address.

    If it not, then you are just a hapless victim of a spammer. If it present, you will need to hunt the cause of the problem. These include a misconfigured mail server, poorly written scripts, and having an intruder.
     
    clancey, Feb 28, 2007 IP
  3. toby

    toby Notable Member

    Messages:
    6,923
    Likes Received:
    269
    Best Answers:
    0
    Trophy Points:
    285
    #3
    thanks clancey, what if i am a victim of spammers? can i do something about it?
     
    toby, Feb 28, 2007 IP
  4. PrimeHost

    PrimeHost Active Member

    Messages:
    116
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    58
    #4
    If you are using scripts all you can do is to make sure your are running the latest versions.

    If you are using cpanel and want to get rid of those bounced emails make sure your default email address is set to :blackhole: so that any email that is sent to that is not a legit email address will be discarded.
     
    PrimeHost, Feb 28, 2007 IP
  5. clixxer

    clixxer Peon

    Messages:
    47
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #5
    Set it to :fail: because then the email doesn't even get to your server.

    Otherwise there is nothing you can do about spammers using your domain as the sender.
     
    clixxer, Mar 1, 2007 IP
  6. PrimeHost

    PrimeHost Active Member

    Messages:
    116
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    58
    #6
    Actually if you set it to :fail: it responds back to the original sender using additional resources, which is why you get the email notifying you of the bounce.

    Set it to :blackhole: it gets deleted.
     
    PrimeHost, Mar 1, 2007 IP
  7. clancey

    clancey Peon

    Messages:
    1,099
    Likes Received:
    63
    Best Answers:
    0
    Trophy Points:
    0
    #7
    Unfortunately, if the messages are being sent from other servers and your email is being used as the return address, there is nothing you can do about.

    A year or so ago, a spammer used my email address for the entire list. I was getting so many rejected email messages that I needed to close that account.
     
    clancey, Mar 1, 2007 IP
  8. Sini

    Sini Peon

    Messages:
    119
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    0
    #8
    This is called email backscattering which is causing lots of problems these days.

    The sender has nothing to do with the domain from which the email appears to be comming from, normally these emails are sent from infected home pc:s etc.

    When an email bouches it sends a bounch notification to reply address although it has nothing to do with the original sender of the domain. These bouches can cause severe email traffic to a server, when there are several bounces every second coming in.

    Unfortunately there is nothing the domain owner or host can do about this. Reporting ip:s etc wont help as there are thousands of pc:s infected and used for these actions. SPF records wont help you.

    To make the load caused by this use :fail: instead of :blackhole: For more information why you should use fail instead of blackhole: http://www.configserver.com/free/fail.html
     
    Sini, Mar 2, 2007 IP