Re: Misuse/Abuse

2020-10-13 Thread Martin Holub
Am 13.10.20 um 16:00 schrieb Daniel Leidert: Am Dienstag, den 13.10.2020, 08:51 +0200 schrieb Knieling, Christian (IANM): To whom this may concern, I got a system message from my mailer daemon lately. It contains cut Message

Re: Misuse/Abuse

2020-10-13 Thread Sven Hartge
On 13.10.20 16:00, Daniel Leidert wrote: Clearly someone tries to run a command put as an address. Out of curiosity: Which kind of vulnerability are they trying to use here? Probably CVE-2019-10149 https://www.qualys.com/2019/06/05/cve-2019-10149/return-wizard-rce-exim.txt Grüße, Sven.

Re: Misuse/Abuse

2020-10-13 Thread Daniel Leidert
Am Dienstag, den 13.10.2020, 08:51 +0200 schrieb Knieling, Christian (IANM): > To whom this may concern, > > I got a system message from my mailer daemon lately. It contains > > cut > Message 1kS01n-0008Kv-Nb has been frozen

Re: Misuse/Abuse

2020-10-13 Thread Paul Wise
On Tue, Oct 13, 2020 at 7:14 AM Knieling, Christian (IANM) wrote: > I don't know if this messages reaches the right persons, but someone may > forward it. You may at least remove the files which are accessible on > paste.debian.net. I forwarded this to the paste.d.n admin and they removed them.

Misuse/Abuse

2020-10-13 Thread Knieling, Christian (IANM)
To whom this may concern, I got a system message from my mailer daemon lately. It contains cut Message 1kS01n-0008Kv-Nb has been frozen (delivery error message). The sender is <>. The following address(es) have yet to be