Koozali.org: home of the SME Server

Vunerable to spammers?

Renegade Master

Vunerable to spammers?
« on: August 08, 2003, 02:36:18 AM »
Hi,

I started a thread on usenet after I had a few strange entries in my httpd log.

www.connectionscentres.com 38.119.65.27 - - [06/Aug/2003:00:52:09 -0400]
"POST http://38.119.65.27:25/ HTTP/1.1" 200 8731 "-" "-"

www.connectionscentres.com 38.119.65.27 - - [06/Aug/2003:00:52:09 -0400]
"CONNECT mail.worlddatacorp.us:25 HTTP/1.0" 200 8691 "-" "-"

www.connectionscentres.com 38.119.65.27 - - [06/Aug/2003:00:52:10 -0400]
"QUIT" 200 0 "-" "-"

www.connectionscentres.com 38.119.65.27 - - [06/Aug/2003:02:00:01 -0400]
"CONNECT mail.worlddatacorp.us:25 HTTP/1.0" 200 8691 "-" "-"


Bottom line is, the kind boffin on usenet suggested my server was open to spammers.  It is an out of the box 5.6, any feedback appreciated.

here is link to the thread

http://groups.google.co.uk/groups?hl=en&lr=&ie=UTF-8&oe=UTF-8&frame=right&th=984c63a49755f05&seekm=PeeYa.1041%24R6.260739%40newsfep2-win.server.ntli.net#link1

Michael Soulier

Re: Vunerable to spammers?
« Reply #1 on: August 08, 2003, 02:44:06 AM »
Renegade Master wrote:
>
> www.connectionscentres.com 38.119.65.27 - -
> [06/Aug/2003:02:00:01 -0400]
> "CONNECT mail.worlddatacorp.us:25 HTTP/1.0" 200 8691 "-" "-"
>
> Bottom line is, the kind boffin on usenet suggested my server
> was open to spammers.  It is an out of the box 5.6, any
> feedback appreciated.

Nonsense.  This is some script kiddie trolling for vulnerable servers. They will be greatly disappointed after trolling yours, assuming the configuration is standard.

Try sending email through your server from outside your private network to confirm. I have no doubt that it will fail.

Also, if you had searched these forums, you'd see that this topic has been covered many times.

Mike

Lloyd Keen

Re: Vunerable to spammers?
« Reply #2 on: August 08, 2003, 09:01:54 AM »
That's like saying that you're more prone to getting unsolicted snail mail because your letter box is blue and the guy next door has a green letter box. It's absolute garbage. EVERYBODY is prone to getting spam and unfortunately the only way to stop it appears to by legislating against it. Have a look at www.cauce.org for some enlightened reading.

James Pybus

Re: Vunerable to spammers?
« Reply #3 on: August 08, 2003, 07:53:09 PM »
What they were saying on the alt.2600 group was that it looked like he had some kind of proxy people were using to send spam. If thats true he could very quickly end up on a lot of blacklists and have loss of bandwidth if his server gets used like this a lot....