Mail server relaying spam, but how?



The problem is over and the machines in question have been rebuilt
from scratch, but I am still curious as to how it could have happened.

Many weeks ago I noticed that I my mail server was dealing with about
4x the amount of mail it normally does. After much digging I was able
to trace it back to my brother's machine (different network, different
location) who happens to be my secondary DNS. I mention the DNS part
since most of the spam being sent to my system was addressed to
domains I host. In any case, the machine sending me all the spam was
not his mail server, but his router.

Since his actual mail server lives within his network, all port 25
traffic should have been diverted to his internal machine, so it
doesn't seem likely to have been a normal open relay issue. His
router had qmail installed on it, and was running FreeBSD 4.5, but
aside from the huge amount of mail coming out of it I didn't see any
abnormal activity on the machine.

So the question becomes, how does a router with port 25/993 directed
to the internal network start relaying gobs of spam and why is all (?)
mail directed at my domains in particular? I didn't see any new
accounts on the machine, nor any strange processes. As soon as I shut
down all of qmail's processes the problem went away.

Any thoughts on this?
_______________________________________________
freebsd-questions@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: Anti-spam filters
    ... be nice to have a multi-user anti-spam system which can have per-user DB. ... There is no per-user procmailrc, all I use procmail for is to crudely detect mail with dubious attachments and file them in the user's windwoes folder, stuff marked up by spamassassin goes to their spam folder and the rest to inbox. ... My frontline mail server no longer accepts mail to herakles.homelinux.org. ... Therefore, when I'm checking my logs and see an attempt to break in using ssh, or send spam I have no hesitation in blocking the entire network as revealed by whois. ...
    (Fedora)
  • Re: blueyonder decide who can email you
    ... > There are lots of ways by which spammers can sneak spam through nodes ... > of problem for the network access provider which it uses. ... mail server, but given that I teach this stuff... ...
    (uk.telecom.broadband)
  • Re: content filtering
    ... opinion on experience that's limited to dealing with domestic US ... Considering that the large majority of spam originates from the US, ... Now all you need is some method of identifying the sender. ... 550 code would come to the attention of the mail server admin who could ...
    (microsoft.public.exchange.admin)
  • Re: anti spam sw?
    ... It only tags suspect mail as spam. ... Bayesian filtering should ALWAYS be the *last* mechanism used to detect spam since it is a guessing scheme based on word weigthing over a historical sample set experienced by just one particular user. ... I also use the MXblocking plug-in because I don't want mails sent from dynamically IP addressed hosts. ... If someone wants to operate their own mail server then let them get a static IP address. ...
    (alt.computer.security)
  • Re: cant send e mail, outlook express
    ... The error message means that your system can't connect with the mail server. ... As well, if you are not actually connecting on a RR network, for example if ... network card and didn't change the default wireless SSID on the router: ... it's possible that someone nearby is using the same SSID but another ISP, ...
    (microsoft.public.windowsxp.help_and_support)