Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Full Disclosure: Re: [SPAM] Spam sent via spambots?

Re: [SPAM] Spam sent via spambots?

From: James Riden <j.riden_at_massey.ac.nz>
Date: Tue, 02 Nov 2004 08:33:21 +1300

Hugo van der Kooij <hvdkooij_at_vanderkooij.org> writes:

> Sendmail logs also show a significant number of false recipients which
> are known to be part of worms that are by now over 6 months old. Like:
>
> Nov 1 07:16:06 gandalf sendmail[17575]: iA16G3QU017575: ruleset=check_rcpt, arg1=<mary@vanderkooij.org>, relay=[221.232.95.12], reject=550 5.7.0 <mary@vanderkooij.org>... - REJECTED: KEEP YOUR VIRUS JUNK!; SEE ALSO: http://hvdkooij.xs4all.nl/email.cms
> Nov 1 07:16:07 gandalf sendmail[17575]: iA16G3QU017575: lost input channel from [221.232.95.12] to MTA after rcpt
> Nov 1 07:16:07 gandalf sendmail[17575]: iA16G3QU017575: from=<maria_at_tencent.com>, size=0, class=0, nrcpts=0, proto=ESMTP, daemon=MTA, relay=[221.232.95.12]
>
> If there are that many worms going around it only shows how easy it is to
> write your own little SMTP engine. Spammers may have deployed similar
> backdoors/trojans/bots/...

A lot of stuff out there will also HELO as <yourdomain>, or the IP
address of your MX. I'm pretty sure it's a worm, because I can't think
how any MTA/MUA could be that broken.

-- 
James Riden / j.riden_at_massey.ac.nz / Systems Security Engineer
Information Technology Services, Massey University, NZ.
GPG public key available at: http://www.massey.ac.nz/~jriden/
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
Received on Nov 01 2004
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]