>This past weekend have been getting SPAM from my server. Looks like
>someone is spoofing my own addresses. When I check the queue, it
>looks like the sending address is [EMAIL PROTECTED] Here is the
>actual message:
>
>Received: from localhost [206.130.189.212] by encode.com
# dig -x 206.130.189.212
; <<>> DiG 8.3 <<>> -x
;; res options: init recurs defnam dnsrch
;; got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 4
;; flags: qr aa rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 2, ADDITIONAL: 2
;; QUERY SECTION:
;; 212.189.130.206.in-addr.arpa, type = ANY, class = IN
;; ANSWER SECTION:
212.189.130.206.in-addr.arpa. 1H IN PTR enc174.encode.com.
>SMTPD32-6.05) id AC39EE80180; Sun, 10 Dec 2000 19:13:45 -0500
>Subject: i_rz YVXU XujqLGruvmS
>Message-Id: <200012101913875.SM00234@localhost>
>
>Then just code like an attachment. I have route for addresses on,
1) "relay for addresses"
AND
2) you MUST have ip spoofing in your border router. (block all
packets entering on your outside interface from your inside addresses)
>but I was thinking how to stop this. I don't have SMTP Auth turned on.
You can't turn it off, you can only turn off the 250-SMTP AUTH announcement.
>That would stop it I assume.
yes, anybody trying to relay from outside of your addresses would
need to do SMTP AUTH.
Len
http://BIND8NT.MEIway.com : Binary for ISC BIND 8.2.3 T9B for NT4 & W2K
http://IMGate.MEIway.com : Build free, hi-perf, anti-spam mail gateways
Please visit http://www.ipswitch.com/support/mailing-lists.html
to be removed from this list.
An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/