Re: [xmail] Getting hammered bad

2011-07-13 Thread fcxmail
In this specific case, the Spammer authenticated with the legituser
account !!!
(as confirmed by account name after the RECV in the log : 'RECV=OK
legitusern...@legitdomain.com')
So before any others solutions, start changing que
legitusern...@legitdomain.com password  (with a complex one) 
And tell youlegituser to completly scan all of it's computers for
trojans/viries/... BEFORE changing the password at its side (to avoid
spammers recover the new password)...

  -Message d'origine-
  De : xmail-boun...@xmailserver.org
[mailto:xmail-boun...@xmailserver.org]De la part de Fred
  Envoye : mercredi 6 juillet 2011 19:36
  A : xmail@xmailserver.org
  Objet : [xmail] Getting hammered bad


  Hello all,



  I need help to fight against spammers, here is a sample of an smtp log
entry:





  mail  mail  72.16.236.115 2011-07-06 12:46:21
ALEXSERVER01.ANDREWALEX.local hotmail.co.uk
vreaus...@vreausutelog.comobbard_d...@hotmail.co.uk SE86331
RECV=OK   legitusern...@legitdomain.com  2507  





  I am receiving sometimes hundreds of this kind of email in a short time. I
have tried black listing the IP and sender domain in spam-adress.tab and
spammers.tab but they just change both and they spam again.



  The email legitusern...@legitdomain.com is a legit user on my server. I am
using spamassassin, spf filter and RBL checks.



  Anyone has any ideas how to block these ers.



  Thanks




___
xmail mailing list
xmail@xmailserver.org
http://xmailserver.org/mailman/listinfo/xmail


Re: [xmail] Getting hammered bad

2011-07-13 Thread Fred
Thanks sir.

 

I am taking actions as we speak. Sometimes the logs, especially SMTP are
kind of hard to interpret.

 

From: xmail-boun...@xmailserver.org [mailto:xmail-boun...@xmailserver.org]
On Behalf Of fcxm...@aquinet.net
Sent: 13 juillet 2011 07:11
To: 'XMail Users Mailing List'
Subject: Re: [xmail] Getting hammered bad

 

In this specific case, the Spammer authenticated with the legituser
account !!!

(as confirmed by account name after the RECV in the log : 'RECV=OK
legitusern...@legitdomain.com')

So before any others solutions, start changing que
mailto:legitusern...@legitdomain.com legitusern...@legitdomain.com
password  (with a complex one) 

And tell youlegituser to completly scan all of it's computers for
trojans/viries/... BEFORE changing the password at its side (to avoid
spammers recover the new password)...

 

-Message d'origine-
De : xmail-boun...@xmailserver.org [mailto:xmail-boun...@xmailserver.org]De
la part de Fred
Envoyé : mercredi 6 juillet 2011 19:36
À : xmail@xmailserver.org
Objet : [xmail] Getting hammered bad

Hello all,

 

I need help to fight against spammers, here is a sample of an smtp log
entry:

 

 

mail  mail  72.16.236.115 2011-07-06 12:46:21
ALEXSERVER01.ANDREWALEX.local hotmail.co.uk
vreaus...@vreausutelog.comobbard_d...@hotmail.co.uk SE86331
RECV=OK   legitusern...@legitdomain.com  2507  

 

 

I am receiving sometimes hundreds of this kind of email in a short time. I
have tried black listing the IP and sender domain in spam-adress.tab and
spammers.tab but they just change both and they spam again.

 

The email legitusern...@legitdomain.com is a legit user on my server. I am
using spamassassin, spf filter and RBL checks…

 

Anyone has any ideas how to block these ers.

 

Thanks

 

 

___
xmail mailing list
xmail@xmailserver.org
http://xmailserver.org/mailman/listinfo/xmail