Koozali.org: home of the SME Server

Have I been used as a relay for SPAM?

Offline jonroberts

  • ****
  • 111
  • +0/-0
    • http://www.westcountrybusiness.com
Have I been used as a relay for SPAM?
« on: October 24, 2005, 10:48:45 AM »
When I came in this morning, I had 400 or so 'Mail Undeliverable' Messages in my inbox.  The mails were all sent over Friday night and were for viagra.

I run SME 6.01 & Lotus Domino, but I don't think the problem is with the server - so sorry if this is taking a liberty with the forum.

I have looked at the return path and although this points to "Sales@westcountrybusiness.com", which is my domain name, but the first mail server is "mail.kingyen.com" on all of the e-mails, so I guess this is an open relay.

I think there are two likely options for this.  One is that one of my kids downloaded something they shouldn't have over the weekend & ran it & that generated all these mails (running AV scans at the moment).  The other is that the mails never came from me at all, but my domain was used as the return path.

Can anyone tell from the info below which its likely to be?

Thanks

----------------------------------------------

Hi. This is the qmail-send program at "domain removed".
I'm afraid I wasn't able to deliver your message to the following addresses.
This is a permanent error; I've given up. Sorry it didn't work out.

<info@domain-removed>:
This address no longer accepts mail.

--- Below this line is a copy of the message.

Return-Path: <sales@westcountrybusiness.com>
Received: (qmail 10964 invoked from network); 21 Oct 2005 23:47:15 -0000
Received: from cpe-24-221-8-40.az.sprintbbd.net (HELO mail.kingyen.com) (24.221.8.40)
  by wpc0069.amenworld.com with SMTP; 21 Oct 2005 23:47:15 -0000
Received: from localhost (helo=localhost)
        by mail.kingyen.com with SMTP id J87Gz003993275;
        Fri, 21 Oct 2005 23:48:34 +0000
Message-Id: <TfiuzT.phpmlr@localhost>
Date: Fri, 21 Oct 2005 23:48:34 +0000
Subject: Just try it...
From: "Lynelle" <sales@westcountrybusiness.com>
To: info@location-maison-brehat.com
X-Mailer: PHP.Mailer v1.4b
MIME-Version: 1.0
Content-Type: text/html; charset=iso-8859-1
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
Importance: Normal
......

Offline Franco

  • *
  • 1,171
  • +0/-0
    • http://contribs.org
Have I been used as a relay for SPAM?
« Reply #1 on: October 24, 2005, 03:17:17 PM »
This is what was used to send the mail:
PHP.Mailer v1.4b
If you didn't put this there yourself, then it's more like a web hack than a SMTP hack.

Offline jonroberts

  • ****
  • 111
  • +0/-0
    • http://www.westcountrybusiness.com
Have I been used as a relay for SPAM?
« Reply #2 on: October 24, 2005, 04:16:45 PM »
Thanks for the feedback.  I've searched the server & can't find anything with (or like) the name PHP.Mailer.

As the mail routing path of the returned mails did not include my mail server (just the return address) I'd like to know if it is possible that it didn't come from my network at all, just from someone using my domain as the return address.  Is that a possibility?
......

Offline Franco

  • *
  • 1,171
  • +0/-0
    • http://contribs.org
Have I been used as a relay for SPAM?
« Reply #3 on: October 24, 2005, 04:32:19 PM »
PHP.Mailer is an application within PHP, not a file that you can find, look at the log files to see what was accessed on your server then look for the script. The message seems to have come from your server!

Offline CharlieBrady

  • *
  • 6,918
  • +3/-0
Have I been used as a relay for SPAM?
« Reply #4 on: October 24, 2005, 04:40:51 PM »
Quote from: "jonroberts"

As the mail routing path of the returned mails did not include my mail server (just the return address) I'd like to know if it is possible that it didn't come from my network at all, just from someone using my domain as the return address.  Is that a possibility?


It's not just a possibility - the evidence points to it.

Notice also the header which starts "Received: from localhost ..." - that indicates that a web form/application is the most likely route of injection of the messages.

You might consider contacting abuse and/or postmaster and/or webmaster at the site which is sending you these bounce messages.

ergozd

Have I been used as a relay for SPAM?
« Reply #5 on: October 24, 2005, 08:04:22 PM »
See the list of projects using phpmailer
http://phpmailer.sourceforge.net/#projects