>This past weekend have been getting SPAM from my server.  Looks like 
>someone is spoofing my own addresses.  When I check the queue, it 
>looks like the sending address is [EMAIL PROTECTED]  Here is the 
>actual message:
>
>Received: from localhost [206.130.189.212]  by encode.com

# dig -x 206.130.189.212

; <<>> DiG 8.3 <<>> -x
;; res options: init recurs defnam dnsrch
;; got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 4
;; flags: qr aa rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 2, ADDITIONAL: 2
;; QUERY SECTION:
;;      212.189.130.206.in-addr.arpa, type = ANY, class = IN

;; ANSWER SECTION:
212.189.130.206.in-addr.arpa.  1H IN PTR  enc174.encode.com.

>SMTPD32-6.05) id AC39EE80180; Sun, 10 Dec 2000 19:13:45 -0500
>Subject: i_rz YVXU XujqLGruvmS
>Message-Id: <200012101913875.SM00234@localhost>
>
>Then just code like an attachment.  I have route for addresses on,

1) "relay for addresses"

AND

2) you MUST have ip spoofing in your border router.  (block all 
packets entering on your outside interface from your inside addresses)

>but I was thinking how to stop this.  I don't have SMTP Auth turned on.

You can't turn it off, you can only turn off the 250-SMTP AUTH announcement.

>That would stop it I assume.

yes, anybody trying to relay from outside of your addresses would 
need to do SMTP AUTH.

Len



http://BIND8NT.MEIway.com : Binary for ISC BIND 8.2.3 T9B for NT4 & W2K
http://IMGate.MEIway.com  : Build free, hi-perf, anti-spam mail gateways

Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/

Reply via email to